Novel Malware Designed to Withstand Analyst Scrutiny
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
The report examines a sophisticated multi-stage malware campaign involving four distinct payloads built to resist analysis and detection. These include PavokwiLoader, a heavily obfuscated C++ loader, RMMCRAT, a custom remote-management agent, a Python-based loader using brute-forced decryption, and a Cobalt Strike beacon. The malware employs advanced evasion techniques including anti-debugging, anti-VM checks, ETW bypassing, and process injection.
Investigation
Two research teams collaborated to trace an intrusion involving SEO poisoning, custom RMM tooling, and Cobalt Strike. The investigation required extensive reverse engineering of the payloads to uncover complex obfuscation techniques, including MBA arithmetic, custom API hashing, and position-dependent ROR ciphers. Analysts also identified infrastructure patterns and a specific technique used to bypass Chrome’s App-Bound Encryption.
Mitigation
Organizations should monitor for unusual process-parent relationships, particularly cases where explorer.exe launches unexpected or suspicious processes. Defenders should also watch for unauthorized registry changes under Windows NT CurrentVersion\Windows keys and unexpected scheduled task creation. Security controls should be configured to identify suspicious use of the APPINFO RPC interface associated with UAC bypass attempts.
Response
When malicious activity is detected, responders should isolate affected endpoints and inspect them for the %APPDATA%\fontcache_ms marker. Review network telemetry for WebSocket connections to unknown domains and unusual TLS fingerprints such as JARM 27d40d40d00040d1dc42d43d00041d6183ff1bfae51ebd88d70384363d525c. Analyze PowerShell Script Block Logging events (Event ID 4104) for obfuscated commands executed through stdin pipes.
Attack Flow
We are still updating this part.
Detections
Python Execution from Suspicious Folders (via cmdline)
The Possibility of Execution Through Hidden PowerShell Command Lines (via cmdline)
Unusual Change Code Page Execution (via cmdline)
Suspicious Powershell Strings (via cmdline)
Short File Name (via cmdline)
Windows Defender Preferences Suspicious Changes (via powershell)
Suspicious Command and Control by Unusual Top Level Domain (TLD) DNS Request (via dns)
IOCs (HashSha256) to detect: Novel Malware Built to Survive the Analyst
IOCs (HashMd5) to detect: Novel Malware Built to Survive the Analyst
IOCs (SourceIP) to detect: Novel Malware Built to Survive the Analyst
IOCs (DestinationIP) to detect: Novel Malware Built to Survive the Analyst
Persistence via Registry Keys and Scheduled Tasks [Windows Registry Event]
Process Injection via ZwCreateUserProcess and ZwQueueApcThread [Windows Process Creation]
Simulation Execution
-
Attack Narrative & Commands: An adversary has gained initial access and seeks to establish persistence to survive a reboot. To evade detection by common AV, they decide to use a known but specific registry hijacking technique. The attacker will attempt to modify the
UserInitMprLogonScriptregistry key to point to a malicious payload. This action is intended to trigger theselection_registryportion of the detection rule by generating a Sysmon Event ID 13. -
Regression Test Script:
# Simulation of Persistence via UserInitMprLogonScript $registryPath = "HKLM:SOFTWAREMicrosoftWindows NTCurrentVersionWinlogon" $name = "UserInitMprLogonScript" $value = "C:WindowsTempmalicious_payload.exe" Write-Host "[+] Attempting to set $name in registry..." try { New-ItemProperty -Path $registryPath -Name $name -Value $value -PropertyType String -Force -ErrorAction Stop Write-Host "[+] Registry modification successful. Check SIEM for Sysmon Event ID 13." } catch { Write-Host "[-] Failed to modify registry. Ensure the script is running as Administrator." -ForegroundColor Red } -
Cleanup Commands:
# Cleanup the malicious registry entry $registryPath = "HKLM:SOFTWAREMicrosoftWindows NTCurrentVersionWinlogon" $name = "UserInitMprLogonScript" if (Get-ItemProperty -Path $registryPath -Name $name -ErrorAction SilentlyContinue) { Remove-ItemProperty -Path $registryPath -Name $name -Force Write-Host "[+] Cleanup successful: Registry key removed." } else { Write-Host "[-] Registry key not found. Nothing to clean." }