Community Night Presentation SANS Secure Australia 2023
Detecting & Hunting
Ransomware Operator Tools:
It’s Easier Than You Think!
Ryan Chapman
Author | FOR528: Ransomware for Incident Responders
About Me – Ryan Chapman | @rj_chap
• 11 years DFIR experience
• SANS Author
• FOR528: Ransomware for Incident Responders
• SANS Instructor
• FOR610: Reverse Engineering Malware
• $dayJob = IR Consultant
• Sponsor Liaison
• .com
[Link]
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 2
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 3
Tonight’s Agenda
Ransomware Sucks! (a.k.a. About Ransomware)
Ransomware Operator Tooling
All Hail the King: PsExec
Data Access & Exfiltration
General Hunting
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 4
Ransomware Sucks!
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 5
Title page
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course
Ransomware Evolution (2015+)
Human-Operated Ransomware (HUMOR)
• Attacks conducted via hands on keyboard
• Enables enterprise-wide distribution
Ransomware-as-a-Service (RaaS)
• Enables anyone to become an affiliate
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 7
Ransomware-as-a-Service (RaaS)
“Affiliate” programs established – it’s a business, literally
Subscription-based Strong business models Operators split profits
leasing program for & multi-faceted with affiliates
ransomware hierarchies (e.g., 30/70 split)
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 8
RaaS Business Model – Roles and Participation
Each role is critical to the success of the “business”
Northwave Security, 2022
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 9
Types of Extortion
Data Data Multi-
Encryption Exfiltration Extortion
• Deploys an • Exfiltrates your • Carrying out DDoS
encryptor payload data and threatens attacks on victim
to encrypt data and to release the data networks
disable network to the public or sell • Contacting
services. it on the darknet if suppliers/partners
you do not pay the • Contacting
requested ransom regulatory bodies
• Calling VIPs/board
and/or investors
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 10
Courtesy of Allan Liska
Twitter: @uuallan
Compromised Real C2 Extortion
Redirect Infrastructure Infrastructure Site
Minutes Hours to Weeks Days to Months
[Link]
[Link] [Link]
[Link] [Link]
AdRecon Endpoints Test ransomware
[Link] [Link] StealBIT
[Link] [Link] WMIC
Phishing [Link] [Link]
[Link] Publish stolen files
MetaSploit Linux Servers to extortion site
7-Zip Deploy ransomware: Domain
AdFind
Controller, SCCM, .bat files,
GPO, PSExec, or SMB
Lazagne
Cobalt ESXi
Web Shell Bloodhound WinSCP/
Credential Strike FileZilla
Stuffing/Re-use or Loader Expanded extortion
RDP PowerSploit ecosystem
Delete Shadow Delete
Mimikatz Windows Copies Backups
PSExec Servers
Rclone
LOLBins
Entry Point
Advanced
GMER
IP Scanner Cover tracks: remove or
ProcessHacker Domain Sell stolen data
MEGASync roll over logs
Exploitation TDSSKiller Controller
Initial Access Remote control: RDP, TeamViewer, AnyDesk, Splashtop, Atera, ScreenConnect, etc. Extortion
Recon & Lateral Movement Exfiltration Deployment
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 11
Ransomware Operator Tooling
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 12
A Paradigm Shift
TAs have moved to readily available tools.
• Free and open source (FOSS)
• GitHub is now the TA’s best friend
• Scripting – TA’s steal one another’s scripts ☺
• Living off the land binaries and scripts ([Link]/lolbas)
• Red team / Emulation / Simulation tools
• Malware-as-a-Service (MaaS)
• Remote Monitoring & Maintenance (RMM) tools
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 13
Bring Your Own Tools (BYOT)
Block/alert on these!
• File sharing sites
• [Link]
• [Link]
• [Link]
• [Link] | [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• [Link]
• See the LOTS project:
• [Link]/lots
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 14
Bring Your Own Tools (BYOT) – DNS Lookups
Alert on DNS/network traffic
7zip • [Link]
AdFind • [Link]
Advanced IP Scanner • [Link]
Angry IP Scanner • [Link]
AnyDesk • [Link]
Process Hacker • [Link]
rclone • [Link]
WinSCP • [Link]
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 15
Identifying Renamed Executables
Threat actors do not always rename executables
• E.g., mimikatz_trunk.zip → [Link]
When they do rename, they often ignore VERSIONINFO
• Description
• Product
• Company
• OriginalFileName
Example OriginalFileName values
• [Link]/exeoriginalname
• [Link]/binaryrename
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 16
Common Bypass Tools & Techniques
Security tool
Advanced LOLBAS
disablers
• GMER | [Link] • Bring Your Own • sc/net
Vulnerable Driver
• [Link] (BYOVD) • tasklist/taskkill
• [Link]/byovd
• [Link]/byovd2
• [Link] • Get-Service/ Stop-
Service
• DLL Hijacking
• [Link]
• [Link]/hijack • Get-Process/ Stop-
Process
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 17
Remote Monitoring and Management (RMM)
Commercial RMM products used often easy to find!
Usually registered in Add/Remove Programs!
• Ensure you have an approved list!
• Whatever is not approved → BLOCK & HUNT!
Commonly seen RMM tools:
• AnyDesk
• Atera
• LogMeIn
• ConnectWise (formerly ScreenConnect)
• Splashtop
• TeamViewer
• Various VNC variations
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 18
RMM Tool Logs
AnyDesk
•%APPDATA%\AnyDesk\[Link]
•%PROGRAMDATA%\AnyDesk\connection_trace.txt
•%PROGRAMDATA%\AnyDesk\ad_svc.trace
ConnectWise/ScreenConnect
•%SYSTEMROOT%\temp\screenconnect\[version]\
•%PROGRAMDATA%\ScreenConnect Client ([fingerprint])\
•%PROGRAMFILES(x86)%\ScreenConnect Client ([fingerprint])\
•%USERPROFILE%\Documents\ConnectWiseControl\Files\
•%USERPROFILE%\Documents\ConnectWiseControl\captures\
• Scripts written to: %SYSTEMROOT%\temp
TeamViewer
•C:\Program Files\TeamViewer\Connections_incoming.txt
•C:\Program Files\TeamViewer\TeamViewer15_Logfile.log
•C:\Program Files\TeamViewer\[Link]
•%APPDATA%\TeamViewer\TeamViewer15_Logfile.log
•%LOCALAPPDATA%\Temp\TeamViewer\[Link]
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 19
Additional RMM Hunting Fun
Check out these fantastic presentations to learn more!
• See Fernando Tomlinson’s “Establishing Connection -
Illuminating Remote Access Artifacts in Windows”
presentation from the SANS DFIR Summit 2022
[Link]
• See Théo Letailleur’s “Legitimate RATS: A Comprehensive
Forensic Analysis of the Usual Suspects” article
[Link]
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 20
All Hail the King: PsExec
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 21
PsExec (SysInternals) – The King of Lateral Movement & Deployment!
Remote system requirements
• SMB service must be enabled.
• File and Print Sharing must be enabled.
• Simple File Sharing must be disabled.
• Administrative Shares must be enabled.
Actual process for running processes remotely
• Opens an SMB session from client to target.
• Accesses the target’s ADMIN$ share & uploads [Link].
• Opens a handle to named pipe \\client\pipe\svcctl to talk to the
Service Control Manager (SCM).
• Calls CreateService using the newly uploaded [Link] as ImageFile.
• Calls StartService to run the service.
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 22
PsExec Process Flow
Stamatoukos, 2020
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 23
PsExec Network Activity (1/2)
Context Information Security, 2018
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 24
PsExec Network Activity (2/2)
Context Information Security, 2018
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 25
PsExec Deployment Examples
• Deployment via PsExec often relies on the @file parameter, which
designates a list of target hosts (a .txt file containing IPs or hostnames):
[Link] -accepteula @C:\Windows\Temp\[Link] -u SAMARAN\
AdminPerz0n -p x86OpcodesAreGR@tefuN123 cmd /c copy
"\\[Link]\c$\Windows\Temp\[Link]" "C:\Windows\Temp"
start [Link] -d @\\[Link]\c$\Windows\Temp\[Link] -u
SAMARAN\AdminPerz0n -p x86OpcodesAreGR@tefuN123 cmd /c
c:\windows\temp\[Link]
• You may also see standard copy or xcopy commands run to copy the
binaries followed by PsExec or WMIC invocation.
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 26
Detecting & Hunting PsExec – Examples
May need tuning if your org uses PsExec legitimately!
• Process creation Event IDs 4688/4689 | Sysmon Event IDs 1 / 5
• File creations : File creations (e.g., Sysmon Event ID 11) for:
• Source: [Link] | Dest: [Link]
• Event IDs 7045 / 7036 / 4697 for service: PSEXESVC
• [7045 / 0x1b85] Source Name: Service Control Manager Strings: ['PSEXESVC',
'%SystemRoot%\\[Link]', 'user mode service', 'demand start',
'LocalSystem'] Computer Name: [Link]
• Registry key that stores End-User License Agreement (EULA) acceptance
• HKEY_CURRENT_USER\Software\Sysinternals\PsExec\EulaAccepted
• Command line strings: -accepteula | @
• Pipe creations: psexesvc*
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 27
Data Access & Exfiltration
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 28
WinZip and 7zip Artifacts
WinZip & 7zip maintain archive data in the registry.
[Link]\Software\Nico Mak
Computing\WinZip\
[Link]\Software\7-Zip\
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 29
WinRAR’s Archive History
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 30
Cloud-Based File Sharing
This may sound ridiculous, because it IS!
• Ransomware actors may literally open a web browser, sign in to a cloud-
sharing site, and upload victim data.
Common sites – BLOCK anything not approved!
• MEGA
• SendSpace
• WeTransfer
• Google Drive | Dropbox | Box | OneDrive
• Cloud-based storage/buckets: AWS | GCP | Azure
Again, see LOTS project: [Link]/lots
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 31
Example LSASS Dump Exfiltration
The Monti ransomware group used DropMeFiles for exfil.
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 32
FileZilla and WinSCP – Common Exfil Tools
FileZilla log locations:
• %APPDATA%\FileZilla\[Link]
• %APPDATA%\FileZilla\[Link]
• %APPDATA%\FileZilla\[Link]
• %APPDATA%\FileZilla\[Link]
• %APPDATA%\FileZilla\*.sqlite3
WinSCP Registry data:
• Username & Remote IP address --
• HKCU\SOFTWARE\Martin Prikryl\WinSCP 2\Configuration\CDCache
• Log File (may or may not exist) --
• HKCU\Software\Martin Prikryl\WinSCP 2\Configuration\Logging
• Local and Remote directories:
• HKCU\SOFTWARE\Martin Prikryl\WinSCP 2\Configuration\History\LocalTarget
• HKCU\SOFTWARE\Martin Prikryl\WinSCP 2\Configuration\History\RemoteTarget
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 33
MEGAsync: MEGA’s First-Party Synchronization Agent
MEGAsync is found in many ransomware cases.
OriginalFileName value: [Link]
Scheduled task: \MEGA\MEGAsync Update Task
%LOCALAPPDATA%\Mega Limited
Executable location:
%LOCALAPPDATA%\MEGAsync
%LOCALAPPDATA%\Mega
Log files located in:
Limited\MEGAsync\logs\
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 34
General Hunting
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 35
Looking for PEs in All the Wrong RIGHT Places
• %AppData% | %ProgramData% | %TEMP% leveraged often
• C:\Users\Public\ & C:\Perflogs\ commonly used for staging
• Monitor for suspicious EXEs in %APPDATA% & %LOCALAPPDATA%
C:\\Users\\.+\\AppData\\(Roaming|Local)\\.*\.exe
• Monitor for EXEs dropped into these directories:
C:\\ProgramData\\.+\.exe
C:\\Users\\Public\\.*\.exe
• Silly %UserProfile% locations
%USERPROFILE%\\(Videos|Music|Pictures)\\.+\.(exe|dll|bat|ps1)
• See also WinSxS, $Recycle Bin & Temporary Internet Files
directories
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 36
%COMSPEC% and Named Pipes – A Match Made in DARKNESS
• %COMSPEC% points to the CLI interpreter (i.e., [Link])
• Note: /c and /k parameters designate commands to run:
%COMSPEC% /c [command]
• Named pipes are part of Interprocess Communication (IPC)
• Check for the following pattern used by Cobalt Strike:
%COMSPEC% /c echo 5f133503c8d > \\.\pipe\c73645
• Regex: ^.*COMSPEC.*echo.*pipe.*$
• General: "\%COMSPEC\%" AND echo AND pipe
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 37
COURSE RESOURCES AND CONTACT INFORMATION
AUTHOR CONTACT
SANS INSTITUTE
Ryan Chapman
11200 Rockville Pike, Suite 200
rchapman@[Link]
N. Bethesda, MD 20852
Twitter: @rj_chap
[Link](7267)
[Link]/in/ryanjchapman/
SANS EMAIL
DFIR RESOURCES GENERAL INQUIRIES: info@[Link]
[Link] REGISTRATION: registration@[Link]
Twitter: @sansforensics TUITION: tuition@[Link]
PRESS/PR: press@[Link]
Learn more in FOR528: Ransomware for Incident Responders | [Link]/course 38