Ghostly Gist

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
In March, PT ESC cyber intelligence specialists recorded activity from the Rare Werewolf group (Rezet, Librarian Ghouls). This time, an archive
data.zip was discovered containing the following file structure:•
Структура компании1111.docx•
any_svc.exe•
clean.ps1•
deploy.ps1•
hider.exe•
monitor.ps1•
run.bat•
svc.conf🤔 Let’s briefly examine the purpose of each file
Структура компании1111.docx — a decoy document, an example of which can be seen in screenshot 1. any_svc.exe — the AnyDesk executable, and svc.conf — the AnyDesk configuration file. hider.exe — the NirCmd executable.However, the most interesting part is the chain of PowerShell scripts launched via the
run.bat script. The clean.ps1 file is responsible for removing already installed instances of AnyDesk on the victim’s system (an example of the script can be seen in screenshot 2). The script code stops all running processes and attempts to locate the installed application via standard paths in the file system and registry.After cleanup, the
deploy.ps1 file is launched (screenshot 3). The script’s algorithm is as follows:1️⃣ Preparing directories and configuration for AnyDesk persistence (the list of directories will be below)
2️⃣ Setting ReadOnly access rights for all configuration files
3️⃣ Launching the executables
any_svc.exe and hider.exe4️⃣ Obtaining the AnyDesk ID via the
--get-id command5️⃣ Sending the obtained ID in a heartbeat request to a Gist page on GitHub (screenshot 4) as a comment. To send such a request, the API link
https://api.github.com/gists/
<gist-id>/comments is used, where gist-id is the note identifier found in the script. The comment itself can be seen below.6️⃣ Creating an LNK file
SystemCheck.lnk in the startup folder, which launches the monitor.ps1 scriptmonitor.ps1 (screenshot 5) — is a script that uses NirCmd commands to hide the windows of the any_svc.exe and AnyDesk.exe processes. If the any_svc.exe process is not running, hider.exe launches it. In addition, the script is used to automatically click buttons in windows titled “Windows Security Alert,” i.e., buttons in the Windows Firewall notification window. Notably, the window title is specified in three languages in the script code — Russian, English, and Ukrainian.😲 An important question remains: where did
data.zip even come from? It’s not like it’s sent in a phishing email. Let’s answer this question as well.Based on a search for scripts similar to
deploy.ps1, a load.ps1 was found, which was located in another archive (screenshot 6). And from the new archive, the parent file was found — a C# executable (fragment in screenshot 7) that decrypts the archive bytes and places it on the victim’s system. Decryption occurs in two stages. First, the byte array undergoes an XOR operation with an 8-byte key. Then, in the array of decoded data, the ZIP archive header is searched for, and the header byte responsible for the compression method is replaced (set to the
Deflate method). All actions take place in a temporary directory, where the dropper’s operation logs are also written to a separate file ghost_trace.log.NEW TARGET: ID=$cid | PC=$cn | USER=$un
# cid = AnyDesk-ID identifier
# cn - computer name ($env:COMPUTERNAME)
# un - username ($env:USERNAME)Code language: plaintext (plaintext)IoCs
Dropper:
c6663dec26224dd3566b4967e9440a7c865ee96af898a444771ba90d033afa55
Archives:
e7302d00c3bef6ff247a37260abdd5ff7eca7c3225b43f56abf3950cc86bf3a8
ca32442aecd8b050dabb5585955df292c4c5b3a9384b90b3377eca3c6200ed21
PowerShell scripts with GitHub requests:
20843993517d8930a56445554b9c93615e4dbaeb6ac66131f2920ea0c966e194
63cf2d21091ca3041f51d3b50f84056909cd44996202557f9161895335e3271cCode language: plaintext (plaintext)IOA
%LocalAppData%\GhostExt
%LocalAppData%\GhostExt\svc.conf
%LocalAppData%\GhostExt\service.conf
%LocalAppData%\GhostExt\any_svc.exe
%LocalAppData%\GhostExt\hider.exe
%TEMP%\GhostExt\ghost_trace.log
%TEMP%\GhostExt\data.zip
%AppData%\Microsoft\Windows\Start Menu\Programs\Startup\SystemCheck.lnkCode language: plaintext (plaintext)#TI #Malware #APT
@ptescalator (X, Max)






More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



