New connection to old techniques

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
During incident investigations, the PT ESC IR team discovered a reverse shell developed in .NET and observed since 2023. It was used by the attackers to control compromised hosts. The malware creates a
cmd.exe process and redirects the input/output stream to a control server, which, as a rule, was one of the hosts in the internal infrastructure. A secure TCP client technique with SSL/TLS was used for the secure network connection.❕ The distinctive feature of this tool is that it is implemented using the
System.Windows.Data component from the Windows Presentation Framework. The technique itself is not new — code execution primitives using System.Windows.Data are actively used in vulnerability exploitation. Let us examine its implementation in more detail.The
Main function (screenshot 1) demonstrates the technique of direct execution via ObjectDataProvider from the System.Windows.Data namespace. Despite the absence of an explicit method call, when the ObjectInstance, MethodParameters, and finally MethodName properties are configured sequentially, the object automatically initiates execution of the specified method (Connect.Start) — directly during its initialization in the Main method. The use of the ExpandedWrapper<Connect, ObjectDataProvider> wrapper indicates borrowing of a pattern from known gadget chains for deserialization, although in this case exploitation occurs directly, without a serialization stage.The
Connect.Start method (screenshot 2) launches the system command shell (cmd.exe) as a child process, asynchronously intercepts its output via the P_OutputDataReceived handler, and redirects the data back to the C2 server, while simultaneously using a custom delegate (Delegate.Combine) for dynamic binding with the Px component responsible for network transmission of commands and results. This architecture allows the attacker to execute arbitrary commands in the context of cmd.exe on the infected machine, while keeping the interaction based on legitimate .NET APIs.The
Net.Run method (screenshot 3) implements the network C2 logic, establishing an encrypted connection to a remote server via TcpClient and SslStream with forced use of TLS 1.2; the IP address and port are taken from encrypted configuration data (screenshot 4) and decrypted on the fly using AES256 in CBC/NoPadding mode, with PBKDF2 (RFC 2898) used to generate the key, taking as input a string value of the password and salt (screenshot 5).To decrypt the configuration data, you can use the following CyberChef recipes:
1. Key generation, into which you must pass
App.PasswordHash and App.SaltKey;2. Decryption algorithm.
🗂 The malicious files were located in legitimate directories:
• C:\Program Files\Internet Explorer\mshealthupdate.exe
• C:\Program Files\Common Files\System\msadds.exe
• C:\Program Files\Common Files\System\ado\msader.exe
To establish persistence in the infrastructure and launch the executable files, the attackers used the Windows Task Scheduler.
This tool is similar to the implementation of the well-known
ncat utility. To invoke the malicious method, the legitimate ObjectDataProvider class from the WPF system library is used, delegates are used to dynamically attach handlers, leaving no clear call chain in the IL code. TLS 1.2 is used to encrypt the console output, and certificate errors are ignored (ValidateServerCertificate => true), which allows it to work with any C2, including dynamic IPs.YARA:
rule MSADDShell {
strings:
$v1 = "net_handlerDelOutDataNet"
$v2 = "P_OutputDataReceived"
$v3 = "add_OutputDataReceived"
$v4 = "SendDataFwd"
$v5 = "OnhandlerDelFwfPx"
$v6 = "OnhandlerDelOutDataNet"
$v7 = "msadds.exe" wide
condition:
uint16(0) == 0x5A4D and 5 of ($v*) and filesize < 100KB
}Code language: PowerShell (powershell)




#IOC #yara #dfir #detect #win #ti #ir
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…






