Case 46E9A7 · Famous breaches · L5 Expert
Your signed softphone is beaconing
Practise as: Incident drill · Interview
Live alert29 March 2023: EDR flags your vendor-signed 3CXDesktopApp.exe loading ffmpeg.dll and calling out to unknown domains on 400 desktops. The vendor's forum says it is an AV false positive.
Interview questionDo you trust the vendor or the EDR, and how do you scope a compromise that arrived through a signed update?
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Trust telemetry over the vendor: trojanized ffmpeg.dll loaded encrypted shellcode appended to a signed d3dcompiler_47.dll
- Appending data without breaking Authenticode abuses CVE-2013-3900; EnableCertPaddingCheck is opt-in, not default
- Stage 1 fetched ICO files from GitHub with encrypted C2 URLs; most hosts got an infostealer, a few got the Gopuram backdoor
- Contain: remove or block the app and its C2, hunt across fleet for second-stage loads, rotate browser-stored creds
- Root cause per Mandiant: a 3CX employee ran trojanized X_TRADER, the first cascading supply-chain attack Mandiant had seen (DPRK)
If the interviewer pushes back
- The app is business-critical telephony. How do you justify pulling it fleet-wide before the vendor confirms?
- What would have stopped one vendor's compromise of X_TRADER from reaching 3CX's build environment?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.