[ << ALL_FEED ]

A complex password won't help

More in General

A complex password won’t help 📮

The practice of the PT ESC IR information security incident response team shows that attackers, upon gaining access to companies’ infrastructure, sometimes embed additional account stealers on the mail server in addition to classic backdoors and tunnels. We already reported on similar malware last year.

For example, during an attack, attackers may gain access to a Microsoft Exchange Server mail server and edit the file C:\Program Files\Microsoft\Exchange Server\V15\FrontEnd\HttpProxy\owa\auth\XX.X.XXXX\scripts\premium\flogon.js, which is an inline script for the main authentication page logon.aspx on OWA (Outlook Web Access).

<%= InlineJavascript("flogon.js") %>
Code language: plaintext (plaintext)


Attackers typically use basic anti-forensic methods, backdating the timestamps of modified files.

$path=".\flogon.js";$time = "2020-01-02 07:24:31";(Get-Item $path).LastWriteTime = $time;(Get-Item $path).CreationTime = $time;(Get-Item $path).LastAccessTime = $time`
Code language: PowerShell (powershell)


As a rule, attackers modify the clkLgn function, which is the login button handler. They add malicious code to the function that intercepts in plaintext all account credentials (usernames and passwords) entered by users when authenticating to OWA.

Let’s look at two recent examples:

1️⃣ In the clkLgn function, a URL of the format https://[REDACTED]/?key1=smthuser&key2=smthpassword is generated, where smthuser is the username and smthpassword is the password of the intercepted account, and a GET request is sent to the command-and-control server (screenshots 1, 2).

2️⃣ In another incident, attackers first added an additional script check.aspx to the server, whose task was to write the intercepted credentials to a log log.png on disk. Attackers could access the log from the internet.

Credential interception, as in the first example, was carried out by a modified clkLgn function, into whose code a new function chklogin was added, which in turn called chk, inside which a URL ./check.aspx?c="smthuser-smthpassword was generated with the intercepted credentials in the “c” parameter, and a GET request was made to the check.aspx script (screenshots 3, 4).

👀 Example of the log.png log:

smthuser-
smthpassword#20250304090723
Code language: plaintext (plaintext)


YARA:

rule PTESC_tool_win_ZZ_clkLgnStealer__Stealer{
  strings:
    $s1 = "//  flogon.js" 
    $s2 = "(\"username\").value"
    $s3 = "(\"password\").value"
    $s4 = "function clkLgn()" 
    $s5 = ".send()" 
  condition:
    all of them and filesize < 20KB
}
Code language: PowerShell (powershell)


Happy hunting!


#ir #hunt #yara #dfir #detect #win
@ptescalator

More from oUth0R

More from oUth0R

More in General