[ << ALL_FEED ]

Exfiltration using PowerShell/C#

More in General

ℹ️ Exfiltration using PowerShell/C#

During an incident investigation, while analyzing Windows event logs on one of the compromised hosts, we discovered that a PowerShell script had been executed to exfiltrate sensitive files from network shares to a server controlled by the attackers 🧐

The required network folder is mounted using the New-SmbMapping, cmdlet, using credentials compromised during one of the earlier stages of the attack. After that, C# code defined inside the PowerShell script is executed, containing the main file upload logic.

The C# program recursively enumerates files located in a specified folder and its subfolders, and uploads to an attacker-controlled web server those files that meet the following conditions:

• size does not exceed 750,000 bytes.
• the file was last modified no more than 130 days ago.

📑 During enumeration, information is written to %APPDATA%\tree.ini, including the full path to the files, their sizes in bytes, the last modification date, and the last access date.

The contents of each file matching the conditions described above are sent via a POST request to the attackers’ web server in multipart/form-data format, in chunks of 16,384 bytes.

The filename parameter receives a file identifier, which is a Base64-encoded string in the following format:


fullpath&&last_write_time&&file_size&&host_name&&current_user&&drive_serial_number

After all files have been processed and uploaded, the tree.ini file is also uploaded to the server, after which it is deleted from the system.

🔦 Analyzing the following Windows security log events can help detect such activity:

1️⃣ Sysmon event ID 11: creation of files in the user folder %AppData% by the powershell.exe process. In our case, files are created with names defined in the code: tree.ini, profiles_int.ini (a database where MD5 hashes of file identifiers are written), sys_error.log and sys_error_ps.log (log files).

2️⃣ Sysmon event ID 3: network connections by the powershell.exe process to internal network hosts on TCP port 445.

3️⃣ Security event ID 4656, 4663: handle request and access to files in the network folder by the powershell.exe process.

4️⃣ Windows PowerShell event ID 800 and Microsoft-Windows-PowerShell/Operational event ID 4103, 4104, containing strings characteristic of the script. In particular, the names of variables and methods defined in the code:


C#: ___directoriesToUpload___, ___fileBase64Id___, ___WritePartInfo, ___SendTreeFileAndTryRemove

💡 An indicator of possible malicious activity is also the presence in network traffic of a large number of HTTP POST requests whose URLs contain Base64-encoded fragments.

👉 SIGMA rule

IoC:


94.158.247.19

#detect #dfir #PowerShell #win
@ptescalator

More from oUth0R

More from oUth0R

More in General