Unusual obfuscation is always beautiful...

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
Unusual obfuscation is always beautiful… 🥰
… it’s just a shame that you have to see it in trojanized open-source packages, and not only at Capture The Flag (CTF) information security competitions.
One of the attacker’s tasks is to make a malicious package that looks legitimate. This allows them to evade detection longer.
We noticed an interesting PyPI campaign that includes the library requests-ml-min authored by scott.fitzgerald. It contains only six Python files:
1️⃣ setup.py. There is execution of ModelInstall at install time, but that’s not a crime: there are many projects that install something extra or compile at this stage.
2️⃣ tests/test_pnotify.py. Nothing unusual.
3️⃣ tests/test_utils.py. Nothing unusual.
4️⃣ resource/resource.py (screenshot 1). Contains an array of 145 UUID identifiers and a concatenation function… 🤪 Original, attempt counted 🙂
5️⃣ src/audit/perf.py (screenshot 2). Collecting system information, packing it into base64, sending it. 👍 Ten detections out of ten for stealer-style system information collection.
6️⃣ src/utils/utils.py (screenshot 3). Implements helper functions. Strings are obfuscated via arrays of ASCII codes… 🏃♀️ Are we solving a reverse CTF task for 100?
About the file resource/resource.py
Behind the obfuscation hides a beautiful downloader + process injector. Beautiful because the downloaded file, which is shellcode, is located at the following URI:
https://storage.googleapis.com/py-pi/python_win
The shellcode will be injected into a separately launched process werfault.exe. The payload is a Cobalt Strike loader.
Actions of the PyPI package during installation:
🤔 Will collect system information (screenshot 2).
🤔 Will send it to https://us-central1-bucket-438814.cloudfunctions.net/ping/api/v1/ping
(by the way, another beautiful URI).
🤔 Will make sure the victim is on the whitelist. To do this, it will get the victim’s domain, hash it with the SHA-256 algorithm, and make sure the hash matches one of seven expected ones. This is a good anti-analysis method, since it complicates the work of researchers 🙂
🤔 If the victim is on the whitelist, it will launch the Cobalt Strike payload.
It’s curious that the code allows preparing a payload for Windows, Linux, and macOS, but the author added only the Windows variant.
We managed to recover the source text for four of the seven hashes:
🌟desktop
🌟abd.local
🌟exttest.local
🌟extprod.local
You can leave your guesses about the nature of these domains in the comments 🤨
Given the list of targets the library limits itself to, this could be a pentest or a bug bounty. At least, let’s hope so — a library this beautiful is not something you come across very often.
#pypi #ti #scs #pyanalysis
@ptescalator (X, Max)


More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



