Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Turla - Snake - day2 -DLL injection into taskhostw.exe is not happening #165

Open
1 task done
vishalsk1 opened this issue Oct 18, 2024 · 1 comment
Open
1 task done

Comments

@vishalsk1
Copy link

Contribution Description

Hi, I am trying to emulate Turla Snake Day 2. I compile snake drivers and installer also compiled EPIC payload to connect my control server. EPIC payload successfully connects to control server and from control server I copied snake payload to victim machine and executed snake installer.
Snake installer successfully loaded vulnerable driver and deleted. Now on edge I browsed some url to make some internet connections. And i can see "C:\Windows\msnsvcx64.dll" is loaded in msedge.exe process. Heartbeat was sent and contrl server responded with "1". now I don't see injection into taskhostw.exe and GUID is not registered on control server. What could be the problem? could you please guide me.

Supporting files or evidence

No response

Where did you find this information?

No response

Operating System

Windows

Code of Conduct

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant