Posts

Using pfSense to selectively allow traffic during dynamic malware analysis

Image
Right now your enterprise network with all its users and systems is a live production lab for any malware or attacker that comes along. If you have an EDR you have an advantageous view of the the endpoints. How about installing that same EDR on your malware analysis system so you can review signatures and TTPs from malware in a controlled environment? You'll be surprised the difference it makes in finding new TTPs. I have always felt it would be nice to be able to allow some traffic out of a dynamic malware analysis lab without letting it all out. As a rule I don't allow malware to talk directly to the Internet without a very good reason to do so. Now with EDR technology available it became crucial to allow the EDR to be able to connect to the mothership while restricting all other traffic to the host only malware network. But once this is setup we can expand things a bit and allow api.ipify.org and other benign traffic. Here is how I did it. If you have a different way I ...

Powershell DNS C2 Notes

I recently took a look at Powershell DNS C2 and found a couple of interesting things. The special case of DNS requests from powershell should be easy enough to identify using an EDR. Using splunk and stats just look for multiple remote port 53 occurrances from powershell. There will be a few but DNS c2 is noisy so a large limit can be used for filtering. Next I took a look at DNSCat https://github.com/lukebaggett/dnscat2-powershell Interestingly powershell does not make the dns request directly but spawns nslookup to do it. Easy enough to make a signature for that. Again, powershell calling nslookup will occur legitimately, but a large filter for occurrences will filter those out. index=edr powershell.exe nslookup.exe parent_path=*\\powershell.exe | stats values(command_line) count by computer_name parent_process_guid | where count>10 Next I went back to some old Oilrig samples which used DNS C2. Nothing new here, just multiple DNS requests directly from powershell. B...

Trickbot Svchost.exe Reconn Commands

https://www.vkremez.com/2018/04/lets-learn-trickbot-implements-network.html Vitali and others have noted that trickbot is running reconn commands. I finally saw them in action and these happen to be children of svchost so I did a quick sig and it looks pretty reliable and quiet. Nothing fancy, just looking for cmd.exe as a child of svchost.exe with common reconn command lines. index=edr svchost.exe process_path=*\\cmd.exe parent_path=*\\svchost.exe  (ipconfig OR "net view" OR "net config" OR nltest OR whoami OR hostname OR tasklist ) | stats values(command_line) count by computer_name process_path Using stats to group the command lines for visibility Previously I had done something more complex based on the JPCERT analysis to detect reconn more generally. https://blogs.jpcert.or.jp/en/2016/01/windows-commands-abused-by-attackers.html @Cyb3rops did this in a very similar manner way before I did. https://github.com/Neo23x0/sigma/blob/master/rules/windo...

An easier method of finding duration of processes

Previously I wrote about calculating duration but I stumbled across a better method. There are two key factors, time stamps in Splunk are numbers and Carbon Black has a process_guid that links the life of the process. We'll use these two things to make a much shorter search. Previous search index=edr event_type=proc process_path=*\\userinit.exe | stats values(type) as types values(_time) as timestamps values(process_path) as proc_path by process_guid | where mvcount(types)>1 | eval end_time=mvindex(timestamp,1) | eval start_time=mvindex(timestamp,0) | eval duration=end_time-start_time | table process_guid types duration timestamps proc_path New search index=edr event_type=proc process_path=*\\userinit.exe | stats range(_time) as duration values(command_line) count by computer_name process_guid As you can see it is much more compact and readable. References: https://docs.splunk.com/Documentation/Splunk/7.3.0/SearchReference/CommonStatsFunctions

Profiling Scheduled Tasks

Watching for suspicious scheduled tasks is always a good thing but there are a lot of them so some creative categorization will be needed. This method is just to view tasks as they execute, not as they are being created. Scheduled tasks should be the child process of svchost.exe so I started by breaking it into several different searches based on our normal suspicious scripting processes. Powershell.exe Cscript.exe Wscript.exe Mshta.exe Cmd.exe I'll use stats and pc counts again to self tune out those that are common to a given number of pcs. I run this back a couple of days so that the auto tuning kicks in. Wscript Tasks index=edr process_path=*\\wscript.exe parent_path=*\\svchost.exe | stats dc(computer_name) as pc_count values(computer_name) count by command_line | Where pc_count Add tuning as necessary to get rid of normal tasks and you "should" be able to get it down to a short list. Repeat with the other target children and add any others that yo...

UAC bypass detection, Children of Eventvwr.exe, CompMgmtLauncher, Fodhelper

BLUF: As Countercept noted, Look for children of:     Eventvwr.exe CompMgmtLauncher.exe Fodhelper.exe A quicky on some old UAC bypasses since it just came up again ITW. SBousseaden shared an Anyrun and some notes on two UAC bypasses: mscfile\shell\open\command ms-settings\shell\open\command mscfile activates from eventvwr.exe or CompMgmtLauncher.exe ms-settings activates using Fodhelper.exe They are well documented. Eventvwr has been patched but CompMgmtLauncher still works, fodhelper, I couldn't test but I assume it works the same way. Testing for the regmods are fine using an EDR but a quick and dirty method is to look for children of the three processes and filter the normal ones. References: https://twitter.com/SBousseaden/status/1143848669407588352 https://twitter.com/countercept/status/842023313467707393 https://github.com/ChaitanyaHaritash/My-Exploits/tree/master/COMPMGMTLAUNCHER_UAC_BYPASS https://enigma0x3.net/2016/08/15/fileless-...

Echo Stdin to Powershell

Image
By now most shops have a good selection of powershell rules, long command lines, netconn, keywords, obfuscation and so on so I am on the lookout for those that might not trigger anything. A recent tweet from Clearsky included an Anyrun trace (always a good source for techniques) that showed cmd echoing commands to powershell without powershell showing the command line so I dug into it a bit. From the references you can see that it isn't new. GBHackers had a good explanation - "Powershell command that ends with Dash “-“ ,that will Execute the command by using standard input (Stdin) and only the dash will appear in powershell.exe’s command line arguments." Cmd using echo  "Powershell -" Also note that while powershell is a child of cmd, it is not the one with the command arguments. Testing showed that the "| powershell -" was not in the command lines from my EDR. Detection There are a couple of ways to go about detecting this....