<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" 
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:wfw="http://wellformedweb.org/CommentAPI/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:meneame="http://meneame.net/faq-es.php"
 >
<channel>
	<title>Menéame: comentarios [3220970]</title>
	<link>http://www.meneame.net</link>
	<image><title>www.meneame.net</title><link>http://www.meneame.net</link><url>http://cdn.mnmstatic.net/img/mnm/eli-rss.png</url></image>
	<description>Sitio colaborativo de publicación y comunicación entre blogs</description>
	<pubDate>Thu, 05 Dec 2019 22:51:24 +0000</pubDate>
	<generator>http://blog.meneame.net/</generator>
	<language>es</language>
	<item>
		<meneame:comment_id>28403540</meneame:comment_id>
		<meneame:link_id>3220970</meneame:link_id>
		<meneame:order>12</meneame:order>
		<meneame:user>ronko</meneame:user>
		<meneame:votes>0</meneame:votes>
		<meneame:karma>7</meneame:karma>
		<meneame:url>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc</meneame:url>
		<title>#12 PyXie, la nueva amenaza que entrega el control de tu PC</title>
		<link>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c012#c-12</link>
		<pubDate>Thu, 05 Dec 2019 22:51:24 +0000</pubDate>
		<dc:creator>ronko</dc:creator>
		<guid>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c012#c-12</guid>
		<description><![CDATA[<p><a class="tooltip c:3220970-5" href="https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c05#c-5" rel="nofollow">#5</a>  Marditos roedore.</p><p>&#187;&nbsp;autor: <strong>ronko</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>28397669</meneame:comment_id>
		<meneame:link_id>3220970</meneame:link_id>
		<meneame:order>11</meneame:order>
		<meneame:user>--606024--</meneame:user>
		<meneame:votes>0</meneame:votes>
		<meneame:karma>6</meneame:karma>
		<meneame:url>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc</meneame:url>
		<title>#11 PyXie, la nueva amenaza que entrega el control de tu PC</title>
		<link>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c011#c-11</link>
		<pubDate>Thu, 05 Dec 2019 09:34:24 +0000</pubDate>
		<dc:creator>--606024--</dc:creator>
		<guid>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c011#c-11</guid>
		<description><![CDATA[<p><a class="tooltip c:3220970-1" href="https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c01#c-1" rel="nofollow">#1</a> Lo que me extraña es que lo hayan hecho en Python en vez de un lenguaje que se compile. De todas formas, si han hecho usado py2exe o PyInstaller no es necesario tener instalado Python para que funcione el programa</p><p>&#187;&nbsp;autor: <strong>--606024--</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>28396691</meneame:comment_id>
		<meneame:link_id>3220970</meneame:link_id>
		<meneame:order>10</meneame:order>
		<meneame:user>h3ndrix</meneame:user>
		<meneame:votes>3</meneame:votes>
		<meneame:karma>30</meneame:karma>
		<meneame:url>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc</meneame:url>
		<title>#10 PyXie, la nueva amenaza que entrega el control de tu PC</title>
		<link>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c010#c-10</link>
		<pubDate>Thu, 05 Dec 2019 07:16:07 +0000</pubDate>
		<dc:creator>h3ndrix</dc:creator>
		<guid>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c010#c-10</guid>
		<description><![CDATA[<p>Les dejo un análisis algo más serio del RAT: <a href="https://threatvector.cylance.com/en_us/home/meet-pyxie-a-nefarious-new-python-rat.html" title="threatvector.cylance.com/en_us/home/meet-pyxie-a-nefarious-new-python-rat.html" rel="nofollow">threatvector.cylance.com/en_us/home/meet-pyxie-a-nefarious-new-python-</a><br />
<br />
Me ha molado bastante la &#34;protección&#34; que lleva, tiene modificados los primeros bytes de cada librería de opcodes para &#34;no poder&#34; decompilarlos y, además, trae su propio interprete python con opcodes remapeados. El link que enlaza sobre decompilar Dropbox también és muy muy muy interesante (<a href="https://www.usenix.org/system/files/conference/woot13/woot13-kholia.pdf" title="www.usenix.org/system/files/conference/woot13/woot13-kholia.pdf" rel="nofollow">www.usenix.org/system/files/conference/woot13/woot13-kholia.pdf</a>).<br />
<br />
Lo que no me gusta del malware es que realiza bastantes conexiones a Internet para bajar código, amén de que modifica claves &#34;muy sensibles&#34; del registro de Windows. Por lo demás, buen trabajo de artesanía <img data-src="https://cdn.mnmstatic.net/v_149/img/menemojis/36/smiley.png" alt=":-)" title=":-)" width="18" height="18" src="https://cdn.mnmstatic.net/v_149/img/g.gif" class="emoji lazy" /></p><p>&#187;&nbsp;autor: <strong>h3ndrix</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>28396666</meneame:comment_id>
		<meneame:link_id>3220970</meneame:link_id>
		<meneame:order>9</meneame:order>
		<meneame:user>sotanez</meneame:user>
		<meneame:votes>0</meneame:votes>
		<meneame:karma>10</meneame:karma>
		<meneame:url>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc</meneame:url>
		<title>#9 PyXie, la nueva amenaza que entrega el control de tu PC</title>
		<link>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c09#c-9</link>
		<pubDate>Thu, 05 Dec 2019 07:11:58 +0000</pubDate>
		<dc:creator>sotanez</dc:creator>
		<guid>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c09#c-9</guid>
		<description><![CDATA[<p><a class="tooltip c:3220970-4" href="https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c04#c-4" rel="nofollow">#4</a> Van a tener que hacerlo pasar por una copia pirata del Doom 2016 para que la gente pique.</p><p>&#187;&nbsp;autor: <strong>sotanez</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>28396506</meneame:comment_id>
		<meneame:link_id>3220970</meneame:link_id>
		<meneame:order>8</meneame:order>
		<meneame:user>Avantasia</meneame:user>
		<meneame:votes>2</meneame:votes>
		<meneame:karma>16</meneame:karma>
		<meneame:url>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc</meneame:url>
		<title>#8 PyXie, la nueva amenaza que entrega el control de tu PC</title>
		<link>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c08#c-8</link>
		<pubDate>Thu, 05 Dec 2019 06:28:31 +0000</pubDate>
		<dc:creator>Avantasia</dc:creator>
		<guid>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c08#c-8</guid>
		<description><![CDATA[<p><a class="tooltip c:3220970-7" href="https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c07#c-7" rel="nofollow">#7</a> <a class="tooltip c:3220970-1" href="https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c01#c-1" rel="nofollow">#1</a>  Es efectivo porque lo que pretende es evadir la detección del antivirus al correr como un proceso de python, lo que si es una técnica más vieja que el pan, y la verdad no se por qué este es especial.<br />
<br />
Si quereis ver ejemplos de como se usa esto para la evasión, en el Veil framework hay 2 técnicas, pyinstaller y py2exe destinadas a ocultar payloads de malware precisamente y tiene ya muchos años, aunque sigue siendo bastante efectivo.<br />
<br />
<a href="https://github.com/Veil-Framework/Veil" title="github.com/Veil-Framework/Veil" rel="nofollow">github.com/Veil-Framework/Veil</a></p><p>&#187;&nbsp;autor: <strong>Avantasia</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>28396325</meneame:comment_id>
		<meneame:link_id>3220970</meneame:link_id>
		<meneame:order>7</meneame:order>
		<meneame:user>Jakeukalane</meneame:user>
		<meneame:votes>3</meneame:votes>
		<meneame:karma>39</meneame:karma>
		<meneame:url>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc</meneame:url>
		<title>#7 PyXie, la nueva amenaza que entrega el control de tu PC</title>
		<link>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c07#c-7</link>
		<pubDate>Thu, 05 Dec 2019 03:21:03 +0000</pubDate>
		<dc:creator>Jakeukalane</dc:creator>
		<guid>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c07#c-7</guid>
		<description><![CDATA[<p>Mi no entender.<br />
Afecta sólo a Windows pero el target son instalaciones de python 2 / python 3 aunque puede venir con ejecutables precargados con el malware.<br />
No parece muy efectivo y tampoco parece diferente a los millones de malwares que hay para windows.<br />
Yo me había preocupado porque tengo python 2 y python 3 como es normal en una instalación de Manjaro, pero vamos, que es otro malware enfocado a Windows...</p><p>&#187;&nbsp;autor: <strong>Jakeukalane</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>28396264</meneame:comment_id>
		<meneame:link_id>3220970</meneame:link_id>
		<meneame:order>6</meneame:order>
		<meneame:user>--625430--</meneame:user>
		<meneame:votes>0</meneame:votes>
		<meneame:karma>7</meneame:karma>
		<meneame:url>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc</meneame:url>
		<title>#6 PyXie, la nueva amenaza que entrega el control de tu PC</title>
		<link>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c06#c-6</link>
		<pubDate>Thu, 05 Dec 2019 02:08:55 +0000</pubDate>
		<dc:creator>--625430--</dc:creator>
		<guid>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c06#c-6</guid>
		<description><![CDATA[<p><a class="tooltip c:3220970-1" href="https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c01#c-1" rel="nofollow">#1</a> Existen cosas como py2exe.</p><p>&#187;&nbsp;autor: <strong>--625430--</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>28395602</meneame:comment_id>
		<meneame:link_id>3220970</meneame:link_id>
		<meneame:order>5</meneame:order>
		<meneame:user>Rorschach_</meneame:user>
		<meneame:votes>0</meneame:votes>
		<meneame:karma>15</meneame:karma>
		<meneame:url>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc</meneame:url>
		<title>#5 PyXie, la nueva amenaza que entrega el control de tu PC</title>
		<link>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c05#c-5</link>
		<pubDate>Wed, 04 Dec 2019 22:17:07 +0000</pubDate>
		<dc:creator>Rorschach_</dc:creator>
		<guid>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c05#c-5</guid>
		<description><![CDATA[<p>Primero fueron Bonnie and Clyde... ahora tenemos a Pyxie y pronto Dyxie. <img data-src="https://cdn.mnmstatic.net/v_149/img/menemojis/36/troll.png" alt=":troll:" title=":troll:" width="18" height="18" src="https://cdn.mnmstatic.net/v_149/img/g.gif" class="emoji lazy" /></p><p>&#187;&nbsp;autor: <strong>Rorschach_</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>28390466</meneame:comment_id>
		<meneame:link_id>3220970</meneame:link_id>
		<meneame:order>4</meneame:order>
		<meneame:user>pieróg</meneame:user>
		<meneame:votes>0</meneame:votes>
		<meneame:karma>7</meneame:karma>
		<meneame:url>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc</meneame:url>
		<title>#4 PyXie, la nueva amenaza que entrega el control de tu PC</title>
		<link>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c04#c-4</link>
		<pubDate>Wed, 04 Dec 2019 10:57:43 +0000</pubDate>
		<dc:creator>pieróg</dc:creator>
		<guid>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c04#c-4</guid>
		<description><![CDATA[<p><a class="tooltip c:3220970-2" href="https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c02#c-2" rel="nofollow">#2</a> esto tiene que pesar un cojón</p><p>&#187;&nbsp;autor: <strong>pieróg</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>28389822</meneame:comment_id>
		<meneame:link_id>3220970</meneame:link_id>
		<meneame:order>3</meneame:order>
		<meneame:user>--569461--</meneame:user>
		<meneame:votes>1</meneame:votes>
		<meneame:karma>14</meneame:karma>
		<meneame:url>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc</meneame:url>
		<title>#3 PyXie, la nueva amenaza que entrega el control de tu PC</title>
		<link>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c03#c-3</link>
		<pubDate>Wed, 04 Dec 2019 09:38:06 +0000</pubDate>
		<dc:creator>--569461--</dc:creator>
		<guid>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c03#c-3</guid>
		<description><![CDATA[<p>Ah pues mira, a ver si utiliza ese control para encontrarme buen porno.</p><p>&#187;&nbsp;autor: <strong>--569461--</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>28389644</meneame:comment_id>
		<meneame:link_id>3220970</meneame:link_id>
		<meneame:order>2</meneame:order>
		<meneame:user>A_D</meneame:user>
		<meneame:votes>3</meneame:votes>
		<meneame:karma>40</meneame:karma>
		<meneame:url>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc</meneame:url>
		<title>#2 PyXie, la nueva amenaza que entrega el control de tu PC</title>
		<link>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c02#c-2</link>
		<pubDate>Wed, 04 Dec 2019 09:16:44 +0000</pubDate>
		<dc:creator>A_D</dc:creator>
		<guid>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c02#c-2</guid>
		<description><![CDATA[<p><a class="tooltip c:3220970-1" href="https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c01#c-1" rel="nofollow">#1</a> señala la fuente original que está compilado como ejecutable:<br />
<br />
<i>&#34;According to cylance research, PyXie has various key features of the following:<br />
<br />
1. Legitimate LogMeIn and Google binaries used to sideload payloads.<br />
2. A Trojanized Tetris app to load and execute Cobalt Strike stagers 3. from internal network shares.<br />
4. Use of a downloader with similarities to Shifu named “Cobalt Mode”.<br />
5. Use of Sharphound to collect active directory information from victims.<br />
6. A custom compiled Python interpreter that uses scrambled opcodes to hinder analysis.<br />
7. Use of a modified RC4 algorithm to encrypt payloads with a unique key per infected host...<br />
<br />
At the final stage, PyXie RAT compiled into executable, In this case, the malware authors compiled their own Python interpreter that loads an archive containing the PyXie RAT bytecode from memory. &#34;</i><br />
<br />
<a href="https://gbhackers.com/python-rat/" title="gbhackers.com/python-rat/" rel="nofollow">gbhackers.com/python-rat/</a></p><p>&#187;&nbsp;autor: <strong>A_D</strong></p>]]></description>
	</item>

	<item>
		<meneame:comment_id>28389594</meneame:comment_id>
		<meneame:link_id>3220970</meneame:link_id>
		<meneame:order>1</meneame:order>
		<meneame:user>GuerraEsPaz</meneame:user>
		<meneame:votes>1</meneame:votes>
		<meneame:karma>15</meneame:karma>
		<meneame:url>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc</meneame:url>
		<title>#1 PyXie, la nueva amenaza que entrega el control de tu PC</title>
		<link>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c01#c-1</link>
		<pubDate>Wed, 04 Dec 2019 09:10:27 +0000</pubDate>
		<dc:creator>GuerraEsPaz</dc:creator>
		<guid>https://www.meneame.net/story/pyxie-nueva-amenaza-entrega-control-tu-pc/c01#c-1</guid>
		<description><![CDATA[<p>para que se ejecute, se necesitara tener el python 2 o 3 en la maquina, verdad? no creo que el usuario medio lo tenga, a menos que el malware lo instale a priori <img data-src="https://cdn.mnmstatic.net/v_149/img/menemojis/36/lol.gif" alt="xD" title=":lol: xD" width="18" height="18" src="https://cdn.mnmstatic.net/v_149/img/g.gif" class="emoji lazy" /></p><p>&#187;&nbsp;autor: <strong>GuerraEsPaz</strong></p>]]></description>
	</item>

</channel>
</rss>
