[ << ALL_FEED ]

New connection to old techniques

More in General

A New Connection to Old Techniques 📡

During incident investigations, the PT ESC IR team discovered a reverse shell developed in .NET and observed since 2023. It was used by the attackers to control compromised hosts. The malware creates a cmd.exe process and redirects the input/output stream to a control server, which, as a rule, was one of the hosts in the internal infrastructure. A secure TCP client technique with SSL/TLS was used for the secure network connection.

❕ The distinctive feature of this tool is that it is implemented using the System.Windows.Data component from the Windows Presentation Framework. The technique itself is not new — code execution primitives using System.Windows.Data are actively used in vulnerability exploitation. Let us examine its implementation in more detail.

The Main function (screenshot 1) demonstrates the technique of direct execution via ObjectDataProvider from the System.Windows.Data namespace. Despite the absence of an explicit method call, when the ObjectInstance, MethodParameters, and finally MethodName properties are configured sequentially, the object automatically initiates execution of the specified method (Connect.Start) — directly during its initialization in the Main method. The use of the ExpandedWrapper<Connect, ObjectDataProvider> wrapper indicates borrowing of a pattern from known gadget chains for deserialization, although in this case exploitation occurs directly, without a serialization stage.

The Connect.Start method (screenshot 2) launches the system command shell (cmd.exe) as a child process, asynchronously intercepts its output via the P_OutputDataReceived handler, and redirects the data back to the C2 server, while simultaneously using a custom delegate (Delegate.Combine) for dynamic binding with the Px component responsible for network transmission of commands and results. This architecture allows the attacker to execute arbitrary commands in the context of cmd.exe on the infected machine, while keeping the interaction based on legitimate .NET APIs.

The Net.Run method (screenshot 3) implements the network C2 logic, establishing an encrypted connection to a remote server via TcpClient and SslStream with forced use of TLS 1.2; the IP address and port are taken from encrypted configuration data (screenshot 4) and decrypted on the fly using AES256 in CBC/NoPadding mode, with PBKDF2 (RFC 2898) used to generate the key, taking as input a string value of the password and salt (screenshot 5).

To decrypt the configuration data, you can use the following CyberChef recipes:

1. Key generation, into which you must pass App.PasswordHash and App.SaltKey;

2. Decryption algorithm.

🗂 The malicious files were located in legitimate directories:
• C:\Program Files\Internet Explorer\mshealthupdate.exe

• C:\Program Files\Common Files\System\msadds.exe

• C:\Program Files\Common Files\System\ado\msader.exe

To establish persistence in the infrastructure and launch the executable files, the attackers used the Windows Task Scheduler.

This tool is similar to the implementation of the well-known ncat utility. To invoke the malicious method, the legitimate ObjectDataProvider class from the WPF system library is used, delegates are used to dynamically attach handlers, leaving no clear call chain in the IL code. TLS 1.2 is used to encrypt the console output, and certificate errors are ignored (ValidateServerCertificate => true), which allows it to work with any C2, including dynamic IPs.

YARA:

rule MSADDShell {
    strings:
        $v1 = "net_handlerDelOutDataNet"
        $v2 = "P_OutputDataReceived"
        $v3 = "add_OutputDataReceived"
        $v4 = "SendDataFwd"
        $v5 = "OnhandlerDelFwfPx"
        $v6 = "OnhandlerDelOutDataNet"
        $v7 = "msadds.exe" wide
    condition:
        uint16(0) == 0x5A4D and 5 of ($v*) and filesize < 100KB
}Code language: PowerShell (powershell)


#IOC #yara #dfir #detect #win #ti #ir
@ptescalator

More from oUth0R

More from oUth0R

More in General