Exfiltration using PowerShell/C#

More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
ℹ️ Exfiltration using PowerShell/C#
During an incident investigation, while analyzing Windows event logs on one of the compromised hosts, we discovered that a PowerShell script had been executed to exfiltrate sensitive files from network shares to a server controlled by the attackers 🧐
The required network folder is mounted using the New-SmbMapping, cmdlet, using credentials compromised during one of the earlier stages of the attack. After that, C# code defined inside the PowerShell script is executed, containing the main file upload logic.
The C# program recursively enumerates files located in a specified folder and its subfolders, and uploads to an attacker-controlled web server those files that meet the following conditions:
• size does not exceed 750,000 bytes.
• the file was last modified no more than 130 days ago.
📑 During enumeration, information is written to %APPDATA%\tree.ini, including the full path to the files, their sizes in bytes, the last modification date, and the last access date.
The contents of each file matching the conditions described above are sent via a POST request to the attackers’ web server in multipart/form-data format, in chunks of 16,384 bytes.
The filename parameter receives a file identifier, which is a Base64-encoded string in the following format:
fullpath&&last_write_time&&file_size&&host_name&¤t_user&&drive_serial_number
After all files have been processed and uploaded, the tree.ini file is also uploaded to the server, after which it is deleted from the system.
🔦 Analyzing the following Windows security log events can help detect such activity:
1️⃣ Sysmon event ID 11: creation of files in the user folder %AppData% by the powershell.exe process. In our case, files are created with names defined in the code: tree.ini, profiles_int.ini (a database where MD5 hashes of file identifiers are written), sys_error.log and sys_error_ps.log (log files).
2️⃣ Sysmon event ID 3: network connections by the powershell.exe process to internal network hosts on TCP port 445.
3️⃣ Security event ID 4656, 4663: handle request and access to files in the network folder by the powershell.exe process.
4️⃣ Windows PowerShell event ID 800 and Microsoft-Windows-PowerShell/Operational event ID 4103, 4104, containing strings characteristic of the script. In particular, the names of variables and methods defined in the code:
C#: ___directoriesToUpload___, ___fileBase64Id___, ___WritePartInfo, ___SendTreeFileAndTryRemove
💡 An indicator of possible malicious activity is also the presence in network traffic of a large number of HTTP POST requests whose URLs contain Base64-encoded fragments.
IoC:
94.158.247.19
#detect #dfir #PowerShell #win
@ptescalator
More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…



