[ << ALL_FEED ]

Unusual obfuscation is always beautiful...

More in General

Unusual obfuscation is always beautiful… 🥰

… it’s just a shame that you have to see it in trojanized open-source packages, and not only at Capture The Flag (CTF) information security competitions.

One of the attacker’s tasks is to make a malicious package that looks legitimate. This allows them to evade detection longer.

We noticed an interesting PyPI campaign that includes the library requests-ml-min authored by scott.fitzgerald. It contains only six Python files:

1️⃣ setup.py. There is execution of ModelInstall at install time, but that’s not a crime: there are many projects that install something extra or compile at this stage.

2️⃣ tests/test_pnotify.py. Nothing unusual.

3️⃣ tests/test_utils.py. Nothing unusual.

4️⃣ resource/resource.py (screenshot 1). Contains an array of 145 UUID identifiers and a concatenation function… 🤪 Original, attempt counted 🙂

5️⃣ src/audit/perf.py (screenshot 2). Collecting system information, packing it into base64, sending it. 👍 Ten detections out of ten for stealer-style system information collection.

6️⃣ src/utils/utils.py (screenshot 3). Implements helper functions. Strings are obfuscated via arrays of ASCII codes… 🏃‍♀️ Are we solving a reverse CTF task for 100?

About the file resource/resource.py

Behind the obfuscation hides a beautiful downloader + process injector. Beautiful because the downloaded file, which is shellcode, is located at the following URI:

https://storage.googleapis.com/py-pi/python_win

The shellcode will be injected into a separately launched process werfault.exe. The payload is a Cobalt Strike loader.

Actions of the PyPI package during installation:

🤔 Will collect system information (screenshot 2).

🤔 Will send it to https://us-central1-bucket-438814.cloudfunctions.net/ping/api/v1/ping
(by the way, another beautiful URI).

🤔 Will make sure the victim is on the whitelist. To do this, it will get the victim’s domain, hash it with the SHA-256 algorithm, and make sure the hash matches one of seven expected ones. This is a good anti-analysis method, since it complicates the work of researchers 🙂

🤔 If the victim is on the whitelist, it will launch the Cobalt Strike payload.

It’s curious that the code allows preparing a payload for Windows, Linux, and macOS, but the author added only the Windows variant.

We managed to recover the source text for four of the seven hashes:
🌟desktop
🌟abd.local
🌟exttest.local
🌟extprod.local

You can leave your guesses about the nature of these domains in the comments 🤨

Given the list of targets the library limits itself to, this could be a pentest or a bug bounty. At least, let’s hope so — a library this beautiful is not something you come across very often.

#pypi #ti #scs #pyanalysis
@ptescalator (X, Max)

More from ti_author

More from ti_author

More in General