DFIR Report Links Intrusion to Tools Used by Three Ransomware Groups

· Original article ↗

Summary

An intrusion began with a fake EarthTime installer that delivered SectopRAT. The attacker used SystemBC and Betruger, stole credentials, and exfiltrated files over unencrypted FTP before being evicted; no ransomware was deployed.

Key points

  • A user ran a malicious executable impersonating DeskSoft’s EarthTime application, which installed SectopRAT. The report also identified an installer search-path vulnerability but said it was not observed being exploited.
  • The attacker deployed SystemBC for proxy tunneling and later Betruger, and used tools including Grixba, AdFind, SharpHound, and NetScan for reconnaissance.
  • The attacker moved mainly through RDP, also using Impacket wmiexec, and performed a DCSync attack and Veeam credential extraction.
  • Files from network shares were archived with WinRAR and transferred using WinSCP over unencrypted FTP, exposing credentials in captured traffic.
  • The attacker was evicted before deploying ransomware, but successfully exfiltrated data.
  • DFIR analysts assessed the operator was likely an affiliate working across multiple ransomware groups, citing tools and artifacts associated with Play, RansomHub, and DragonForce.

Article Details

Attack Vectors
  • A user executed a malicious EarthTime.exe impersonating DeskSoft’s EarthTime application; its execution chain deployed SectopRAT.
  • SectopRAT injected into MSBuild.exe, which retrieved its C2 configuration from Pastebin. The actor subsequently deployed SystemBC for proxy tunneling.
  • The actor used a SystemBC tunnel and RDP to move among compromised systems, and later used Impacket’s wmiexec for remote command execution.
  • The actor archived file-share data with WinRAR and exfiltrated the archives with WinSCP over unencrypted FTP.
  • The actor used Grixba, SharpHound, AdFind, and SoftPerfect NetScan for network and Active Directory reconnaissance.
  • The actor later deployed Betruger and a key-protected vhd.dll loader. The report could not determine the purpose or malware family of the loader’s encrypted payload.
Defensive Notes
  • The actor was evicted before any ransomware deployment was observed, but data exfiltration had occurred.
  • Packet capture exposed the FTP session and credentials in clear text because the actor used FTP rather than SFTP.
  • The report identifies detection opportunities in SectopRAT network alerts, SystemBC-associated outbound RDP activity, PowerShell script block logs, Windows security logs, Sysmon events, and file artifacts associated with Grixba and SharpHound.
  • Researchers found an uncontrolled search-path behavior in the EarthTime installer and reported that it applied to DeskSoft software, but did not observe the actor exploit it.

Indicators of compromise

TypeIndicatorContext
DOMAIN504e1c95[.]host[.]njalla[.]netBetruger C2 domain contacted by ccs.exe.
DOMAIN504ec1c95[.]host[.]njalla[.]netSeparately spelled domain that the report says OSINT classified as phishing; its relationship to the reported Betruger C2 spelling is unclear.
IPV4144[.]202[.]61[.]209FTP server used to exfiltrate archived victim data.
IPV4149[.]28[.]101[.]219SystemBC infrastructure contacted by WakeWordEngine.dll/conhost.dll.
IPV445[.]141[.]87[.]55Defanged form of the SectopRAT C2 address identified in network alerts.
IPV480[.]78[.]28[.]149Betruger infrastructure listed in the report’s atomic indicators.
MD512011c44955fd6631113f68a99447515Hash listed for adfind.exe used in the intrusion.
MD527f7186499bc8d10e51d17d3d6697bc5Hash listed for netscan.exe used to scan the victim network.
MD55675a7773f6d3224bfefdc01745f8411Hash listed for ccs.exe, identified as Betruger.
MD571f703024c3d3bfc409f66bb61f971a0Hash listed for malicious earthtime.exe.
MD5829a9dfd2cdcf50519a1cec1f529854bHash listed for sh.exe, identified as a renamed SharpHound binary.
MD588df27b6e794e3fd5f93f28b1ca1d3d0Hash listed for the deployed Grixba executable grb_net.exe.
MD595c96de7dcb5a643559ac66045559cc9Hash listed for the suspicious vhd.dll loader.
MD5abb2a6a0f771ab20ce2037d2c4ef5783Hash listed for the deployed Grixba executable gt_net.exe.
MD5c6f92d1801d7d212282a6dd8f11b44feHash listed for the actor’s FS64.exe file-collection tool.
MD5e963d598a86c5ee428a2eefa34d1ffbbHash listed for the SystemBC DLL, named wakewordengine.dll or conhost.dll.
SHA1142294249feb536e0edbe6e2de3eb3c3415ecf39Hash listed for the SystemBC DLL, named wakewordengine.dll or conhost.dll.
SHA12114d655805f465d11b720830d150c145039bcd4Hash listed for the deployed Grixba executable grb_net.exe.
SHA14f4f8cf0f9b47d0ad95d159201fe7e72fbc8448dHash listed for adfind.exe used in the intrusion.
SHA152332ce16ee0c393b8eea6e71863ad41e3caeafdHash listed for netscan.exe used to scan the victim network.
SHA15bf41754bfb3a18611b2a02f7f385960ed24f8e1Hash listed for sh.exe, identified as a renamed SharpHound binary.
SHA168b6d0cc1430e2d4f70e2ba5026d1c4847324269Hash listed for the suspicious vhd.dll loader.
SHA1ac0fcbc148e45e172c9be0acf9c307186f898803Hash listed for the deployed Grixba executable gt_net.exe.
SHA1c0e5e4b5fcbd0a30b042e602d99a6ee81ad5d8d7Hash listed for ccs.exe, identified as Betruger.
SHA1d15d45d9d9a8ef7a9f048d74b386f620f3b82576Hash listed for the actor’s FS64.exe file-collection tool.
SHA1f24fc14f39c160b54dc3b2fbd1eba605ec0eb04fHash listed for malicious earthtime.exe.
SHA25618f0898d595ec054d13b02915fb7d3636f65b8e53c0c66b3c7ee3b6fc37d3566Hash listed for netscan.exe used to scan the victim network.
SHA2566f9326224e6047458e692cd27aeb1054b9381c67aaf2fe238dbebfbc916c4b33Hash listed for the SystemBC DLL, named wakewordengine.dll or conhost.dll.
SHA256a4bc6bebabb52ed9816987b77ebae6ef70e174533a643aea6265bdf1ed9b8952Hash listed for the suspicious vhd.dll loader.
SHA256a7240d8a7aee872c08b915a58976a1ddee2ff5a8a679f78ec1c7cf528f40deedHash listed for sh.exe, identified as a renamed SharpHound binary.
SHA256ae7c31d4547dd293ba3fd3982b715c65d731ee07a9c1cc402234d8705c01dfcaHash listed for ccs.exe, identified as Betruger.
SHA256aeaf7cc7364a44b381af9f317fe6f78c2717217800b93bee8839ab3e56233254Hash listed for the deployed Grixba executable gt_net.exe.
SHA256bcff246f0739ed98f8aa615d256e7e00bc1cb24c8cabaea609b25c3f050c7805Hash listed for malicious earthtime.exe.
SHA256c92c158d7c37fea795114fa6491fe5f145ad2f8c08776b18ae79db811e8e36a3Hash listed for adfind.exe used in the intrusion.
SHA256e1521e077079032df974c7ae39e4737cdb4f05c6ded677ed5446167466eeb899Hash listed for the actor’s FS64.exe file-collection tool.
SHA256f8810179ab033a9b79cd7006c1a74fbcde6ed0451c92fbb8c7ce15b52499353aHash listed for the deployed Grixba executable grb_net.exe.

MITRE ATT&CK

T1003.001 · LSASS MemoryThe Betruger backdoor accessed LSASS process memory to harvest credentials.T1003.006 · DCSyncThe actor performed DCSync against a domain controller using a privileged account.T1016 · System Network Configuration DiscoveryThe actor ran ipconfig and other commands to inspect network configuration.T1018 · Remote System DiscoveryGrixba and other discovery commands enumerated systems in the victim network.T1021.001 · Remote Desktop ProtocolThe actor used RDP to move from the beachhead to domain controllers and other servers.T1036 · MasqueradingMalicious executables impersonated EarthTime and carried metadata mimicking security products.T1046 · Network Service DiscoveryGrixba and NetScan scanned internal hosts and services.T1047 · Windows Management InstrumentationThe actor used Impacket’s wmiexec to run reconnaissance commands on a domain controller.T1048 · Exfiltration Over Alternative ProtocolThe actor used WinSCP to exfiltrate the archives to an external FTP server.T1055 · Process InjectionSectopRAT injected into MSBuild.exe, and ccs.exe later injected into numerous running processes.T1059.001 · PowerShellThe actor executed PowerShell for Veeam credential retrieval and Active Directory computer enumeration.T1059.003 · Windows Command ShellThe actor executed reconnaissance commands through cmd.exe, including remotely through wmiexec.T1069.001 · Local GroupsThe actor ran net localgroup during local discovery.T1069.002 · Domain GroupsThe actor ran net group "Domain Admins" /domain.T1070.006 · TimestompGT_NET.exe changed timestamps on its ExportData.db output, including setting a future date.T1083 · File and Directory DiscoveryThe actor inspected files on shared drives, including an insurance policy document, before archiving data.T1087.001 · Local AccountBetruger-spawned commands included net user for user enumeration.T1087.002 · Domain AccountThe actor used Active Directory queries and commands to enumerate domain users.T1090 · ProxySystemBC provided proxy access used for RDP connections into the victim network.T1098.007 · Additional Local or Domain GroupsThe actor added the newly created Admon account to the local Administrators group.T1119 · Automated CollectionThe actor used FS64.exe to automate collection of files from a remotely mounted share.T1127.001 · MSBuildThe SectopRAT execution chain injected malware into MSBuild.exe.T1136.001 · Local AccountThe actor created the local Admon account on the beachhead host.T1204.002 · Malicious FileA user executed the malicious EarthTime.exe file after downloading it.T1482 · Domain Trust DiscoveryThe actor ran nltest commands to examine domain trusts.T1547.001 · Registry Run Keys / Startup FolderA shortcut placed in the Startup folder launched the renamed malicious EarthTime executable at user logon.T1555 · Credentials from Password StoresA PowerShell script queried the VeeamBackup Credentials table and used Veeam’s ProtectedStorage class to decrypt passwords.T1560.001 · Archive via UtilityThe actor used WinRAR to archive selected file shares before exfiltration.T1562.001 · Disable or Modify ToolsThe actor modified Windows Defender policy registry keys in an attempt to disable multiple protections.T1569.002 · Service ExecutionThe actor used PsExec to run SystemBC with SYSTEM privileges on a domain controller.T1570 · Lateral Tool TransferThe actor deployed SystemBC across compromised servers during lateral movement.T1572 · Protocol TunnelingThe actor established a SystemBC tunnel to support access into the internal network.

People

Threat Actors

Malware

Vendors

Products

Tools

Countries

Related Articles