Frame-14

Privacy Ninja

        • DATA PROTECTION

        • Email Spoofing Prevention
        • Check if your organization email is vulnerable to hackers and put a stop to it. Receive your free test today!
        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • AntiHACK Phone
        • Boost your smartphone’s security with enterprise-level encryption, designed by digital forensics and counterintelligence experts, guaranteeing absolute privacy for you and up to 31 others, plus a guest user, through exclusive access.

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$3,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Secure your digital frontiers with our API penetration testing service, meticulously designed to identify and fortify vulnerabilities, ensuring robust protection against cyber threats.

        • Network Penetration Testing
        • Strengthen your network’s defenses with our comprehensive penetration testing service, tailored to uncover and seal security gaps, safeguarding your infrastructure from cyber attacks.

        • Mobile Penetration Testing
        • Strengthen your network’s defenses with our comprehensive penetration testing service, tailored to uncover and seal security gaps, safeguarding your infrastructure from cyber attacks.

        • Web Penetration Testing
        • Fortify your web presence with our specialized web penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats.

        • RAPID DIGITALISATION

        • OTHERS

TrickBot Malware Uses Obfuscated Windows Batch Script To Evade Detection

https://open.spotify.com/show/3Gmj15x6cGrgJEzmGnDTTj

TrickBot Malware Uses Obfuscated Windows Batch Script To Evade Detection

With the 100th release of TrickBot, the malware came equipped with new and advanced evasive capabilities. One such capability is its use of an obfuscated batch script launcher to jumpstart malicious executables.

The fact that batch scripts need no interpreter but Microsoft Windows’ inbuilt command prompt makes this evasion technique self-contained and minimalistic.

TrickBot deploys ransomware via obfuscated BAT scripts

Over the weekend, BleepingComputer’s Lawrence Abrams analyzed the hundredth build of TrickBot and its new features.

TrickBot is a malware infection commonly installed via malicious phishing emails or other malware. When installed, TrickBot will quietly run on a victim’s computer while it downloads other modules to perform different tasks.

TrickBot is known to finish an attack by giving access to threat actors who deploy either the Ryuk or Conti ransomware on the compromised network.

In our analysis, BleepingComputer had observed a BAT script launcher.bat being run by a scheduled task set up by TrickBot.

scheduled task launching launcher.bat trickbot
Scheduled task that runs launcher.bat
Source: BleepingComputer

Both the launcher.bat and the executable it launches are present in the same directory, as observed by BleepingComputer, whose location looks like:

C:\Users\(username)\AppData\Roaming\IdentitiesXXXXXXXXXX\

Also Read: How To Send Mass Email Without Showing Addresses: 2 Great Workarounds

Yet, the use of an obfuscated batch script, shown below, to launch the executable is likely another feature to fly under the radar of enterprise security products.

trickbot obfuscated script bleepingcomputer analysis
The obfuscated batch script launcher.bat  further runs the EXE payload
Source: BleepingComputer

Recently, researchers at Huntress Labs discovered another TrickBot sample that used a similar batch script with over 40 lines of obfuscated code.

When deciphered, all the code did was launch the malware, an action that could have been triggered by just a single line of code:

start C:\Users\ksando.2HZ\AppData\Roaming\Identities1603031315\ulib8b4.exe

The binary in question, “ulib8b4.exe” is TrickBot’s payload that performs a wide range of malicious activity, including stealing a domain’s Active Directory Services databasespreading laterally on a networkscreenlockingstealing cookies and browser passwords, and stealing OpenSSH keys.

“System administrators often make use of batch scripting to make their lives easier and speed up their workflow,” says John Hammond, Senior Security Researcher at Huntress Labs.

“But since this offers great access to the computer system, threat actors and malware families take advantage of .bat files just as well.”

Hammond notes although antivirus products could easily scan plain-text batch scripts, the fact an attacker has gone through multiple steps to obfuscate a simple one-line command would make it virtually impossible for an “off-the-shelf” EDR or signature-based antivirus product to detect such samples.

Further, the signature detection can be avoided given there are various ways an attacker could obfuscate the same payload, each producing a different signature.

“On the surface, this code is completely unintelligible. It looks like random letters, in a random order, with random percent-signs thrown all around. But cmd.exe will interpret it and execute it, and that old-school shell is the tried and true built-in that hackers know will be on a target system,” said Hammond.

Also Read: How a Smart Contract Audit Works and Why it is Important

Why are obfuscated batch scripts uniquely a problem?

BleepingComputer asked Hammond, considering obfuscation techniques are not limited to batch scripts why was the use of BAT files in malware uniquely a problem.

In other words, NodeJS files and Python scripts that contain plain text code, rather than binary data, could be just as well obfuscated.

Hammond told BleepingComputer, “You’re absolutely right—it could very well have been any file or any different language of code. I think the most interesting gimmick with the BAT/cmd.exe script is that it is native and inherent to a Windows operating system, so it doesn’t need any external compiler or some other means to get the code to execute on the target.”

Furthermore, the researcher told us, since all of the characters in the batch script were ASCII printable characters, rather than binary code, it was easier to transmit the script over the wire while bypassing the scrutiny of antivirus programs.

“We talk a lot about ‘live-off-the-land binaries’ and this is a peculiar one because it is not so much a ‘binary,’ but a trick to sort of weaponizing one.”

“And of course, with all the characters being ASCII printable characters, this snippet can be easily sent over the wire, and since there aren’t any glaring ‘bad strings’ or malicious signatures, an EDR or AV program could overlook it,” the researcher told BleepingComputer.

Huntress Labs’ detailed insights on the obfuscation technique can be found in their report.

An improved version of this obfuscation technique has also been demonstrated by Hammond on YouTube.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us