[ << ALL_FEED ]

Ghostly Gist

More in General

Ghostly Gist 😏

In March, PT ESC cyber intelligence specialists recorded activity from the Rare Werewolf group (Rezet, Librarian Ghouls). This time, an archive data.zip was discovered containing the following file structure:

• Структура компании1111.docx
• any_svc.exe
• clean.ps1
• deploy.ps1
• hider.exe
• monitor.ps1
• run.bat
• svc.conf

🤔 Let’s briefly examine the purpose of each file

Структура компании1111.docx — a decoy document, an example of which can be seen in screenshot 1. any_svc.exe — the AnyDesk executable, and svc.conf — the AnyDesk configuration file. hider.exe — the NirCmd executable.

However, the most interesting part is the chain of PowerShell scripts launched via the run.bat script. The clean.ps1 file is responsible for removing already installed instances of AnyDesk on the victim’s system (an example of the script can be seen in screenshot 2). The script code stops all running processes and attempts to locate the installed application via standard paths in the file system and registry.

After cleanup, the deploy.ps1 file is launched (screenshot 3). The script’s algorithm is as follows:

1️⃣ Preparing directories and configuration for AnyDesk persistence (the list of directories will be below)

2️⃣ Setting ReadOnly access rights for all configuration files

3️⃣ Launching the executables any_svc.exe and hider.exe

4️⃣ Obtaining the AnyDesk ID via the --get-id command

5️⃣ Sending the obtained ID in a heartbeat request to a Gist page on GitHub (screenshot 4) as a comment. To send such a request, the API link https://api.github.com/gists/ <gist-id>/comments is used, where gist-id is the note identifier found in the script. The comment itself can be seen below.

6️⃣ Creating an LNK file SystemCheck.lnk in the startup folder, which launches the monitor.ps1 script

monitor.ps1 (screenshot 5) — is a script that uses NirCmd commands to hide the windows of the any_svc.exe and AnyDesk.exe processes. If the any_svc.exe process is not running, hider.exe launches it. In addition, the script is used to automatically click buttons in windows titled “Windows Security Alert,” i.e., buttons in the Windows Firewall notification window. Notably, the window title is specified in three languages in the script code — Russian, English, and Ukrainian.

😲 An important question remains: where did data.zip even come from? It’s not like it’s sent in a phishing email. Let’s answer this question as well.

Based on a search for scripts similar to deploy.ps1, a load.ps1 was found, which was located in another archive (screenshot 6). And from the new archive, the parent file was found — a C# executable (fragment in screenshot 7) that decrypts the archive bytes and places it on the victim’s system.

Decryption occurs in two stages. First, the byte array undergoes an XOR operation with an 8-byte key. Then, in the array of decoded data, the ZIP archive header is searched for, and the header byte responsible for the compression method is replaced (set to the Deflate method). All actions take place in a temporary directory, where the dropper’s operation logs are also written to a separate file ghost_trace.log.

NEW TARGET: ID=$cid | PC=$cn | USER=$un
# cid = AnyDesk-ID identifier
# cn - computer name ($env:COMPUTERNAME)
# un - username ($env:USERNAME)Code language: plaintext (plaintext)


IoCs

Dropper:
c6663dec26224dd3566b4967e9440a7c865ee96af898a444771ba90d033afa55

Archives:
e7302d00c3bef6ff247a37260abdd5ff7eca7c3225b43f56abf3950cc86bf3a8
ca32442aecd8b050dabb5585955df292c4c5b3a9384b90b3377eca3c6200ed21

PowerShell scripts with GitHub requests:
20843993517d8930a56445554b9c93615e4dbaeb6ac66131f2920ea0c966e194
63cf2d21091ca3041f51d3b50f84056909cd44996202557f9161895335e3271cCode language: plaintext (plaintext)


IOA

%LocalAppData%\GhostExt
%LocalAppData%\GhostExt\svc.conf
%LocalAppData%\GhostExt\service.conf
%LocalAppData%\GhostExt\any_svc.exe
%LocalAppData%\GhostExt\hider.exe

%TEMP%\GhostExt\ghost_trace.log
%TEMP%\GhostExt\data.zip

%AppData%\Microsoft\Windows\Start Menu\Programs\Startup\SystemCheck.lnkCode language: plaintext (plaintext)


#TI #Malware #APT
@ptescalator (X, Max)

More from ti_author

More from ti_author

More in General