DFIR Report Links Intrusion to Tools Used by Three Ransomware Groups

Summary
An intrusion began with a fake EarthTime installer that delivered SectopRAT. The attacker used SystemBC and Betruger, stole credentials, and exfiltrated files over unencrypted FTP before being evicted; no ransomware was deployed.
Key points
- A user ran a malicious executable impersonating DeskSoft’s EarthTime application, which installed SectopRAT. The report also identified an installer search-path vulnerability but said it was not observed being exploited.
- The attacker deployed SystemBC for proxy tunneling and later Betruger, and used tools including Grixba, AdFind, SharpHound, and NetScan for reconnaissance.
- The attacker moved mainly through RDP, also using Impacket wmiexec, and performed a DCSync attack and Veeam credential extraction.
- Files from network shares were archived with WinRAR and transferred using WinSCP over unencrypted FTP, exposing credentials in captured traffic.
- The attacker was evicted before deploying ransomware, but successfully exfiltrated data.
- DFIR analysts assessed the operator was likely an affiliate working across multiple ransomware groups, citing tools and artifacts associated with Play, RansomHub, and DragonForce.
Article Details
- Attack Vectors
- A user executed a malicious EarthTime.exe impersonating DeskSoft’s EarthTime application; its execution chain deployed SectopRAT.
- SectopRAT injected into MSBuild.exe, which retrieved its C2 configuration from Pastebin. The actor subsequently deployed SystemBC for proxy tunneling.
- The actor used a SystemBC tunnel and RDP to move among compromised systems, and later used Impacket’s wmiexec for remote command execution.
- The actor archived file-share data with WinRAR and exfiltrated the archives with WinSCP over unencrypted FTP.
- The actor used Grixba, SharpHound, AdFind, and SoftPerfect NetScan for network and Active Directory reconnaissance.
- The actor later deployed Betruger and a key-protected vhd.dll loader. The report could not determine the purpose or malware family of the loader’s encrypted payload.
- Defensive Notes
- The actor was evicted before any ransomware deployment was observed, but data exfiltration had occurred.
- Packet capture exposed the FTP session and credentials in clear text because the actor used FTP rather than SFTP.
- The report identifies detection opportunities in SectopRAT network alerts, SystemBC-associated outbound RDP activity, PowerShell script block logs, Windows security logs, Sysmon events, and file artifacts associated with Grixba and SharpHound.
- Researchers found an uncontrolled search-path behavior in the EarthTime installer and reported that it applied to DeskSoft software, but did not observe the actor exploit it.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | 504e1c95[.]host[.]njalla[.]net | Betruger C2 domain contacted by ccs.exe. |
| DOMAIN | 504ec1c95[.]host[.]njalla[.]net | Separately spelled domain that the report says OSINT classified as phishing; its relationship to the reported Betruger C2 spelling is unclear. |
| IPV4 | 144[.]202[.]61[.]209 | FTP server used to exfiltrate archived victim data. |
| IPV4 | 149[.]28[.]101[.]219 | SystemBC infrastructure contacted by WakeWordEngine.dll/conhost.dll. |
| IPV4 | 45[.]141[.]87[.]55 | Defanged form of the SectopRAT C2 address identified in network alerts. |
| IPV4 | 80[.]78[.]28[.]149 | Betruger infrastructure listed in the report’s atomic indicators. |
| MD5 | 12011c44955fd6631113f68a99447515 | Hash listed for adfind.exe used in the intrusion. |
| MD5 | 27f7186499bc8d10e51d17d3d6697bc5 | Hash listed for netscan.exe used to scan the victim network. |
| MD5 | 5675a7773f6d3224bfefdc01745f8411 | Hash listed for ccs.exe, identified as Betruger. |
| MD5 | 71f703024c3d3bfc409f66bb61f971a0 | Hash listed for malicious earthtime.exe. |
| MD5 | 829a9dfd2cdcf50519a1cec1f529854b | Hash listed for sh.exe, identified as a renamed SharpHound binary. |
| MD5 | 88df27b6e794e3fd5f93f28b1ca1d3d0 | Hash listed for the deployed Grixba executable grb_net.exe. |
| MD5 | 95c96de7dcb5a643559ac66045559cc9 | Hash listed for the suspicious vhd.dll loader. |
| MD5 | abb2a6a0f771ab20ce2037d2c4ef5783 | Hash listed for the deployed Grixba executable gt_net.exe. |
| MD5 | c6f92d1801d7d212282a6dd8f11b44fe | Hash listed for the actor’s FS64.exe file-collection tool. |
| MD5 | e963d598a86c5ee428a2eefa34d1ffbb | Hash listed for the SystemBC DLL, named wakewordengine.dll or conhost.dll. |
| SHA1 | 142294249feb536e0edbe6e2de3eb3c3415ecf39 | Hash listed for the SystemBC DLL, named wakewordengine.dll or conhost.dll. |
| SHA1 | 2114d655805f465d11b720830d150c145039bcd4 | Hash listed for the deployed Grixba executable grb_net.exe. |
| SHA1 | 4f4f8cf0f9b47d0ad95d159201fe7e72fbc8448d | Hash listed for adfind.exe used in the intrusion. |
| SHA1 | 52332ce16ee0c393b8eea6e71863ad41e3caeafd | Hash listed for netscan.exe used to scan the victim network. |
| SHA1 | 5bf41754bfb3a18611b2a02f7f385960ed24f8e1 | Hash listed for sh.exe, identified as a renamed SharpHound binary. |
| SHA1 | 68b6d0cc1430e2d4f70e2ba5026d1c4847324269 | Hash listed for the suspicious vhd.dll loader. |
| SHA1 | ac0fcbc148e45e172c9be0acf9c307186f898803 | Hash listed for the deployed Grixba executable gt_net.exe. |
| SHA1 | c0e5e4b5fcbd0a30b042e602d99a6ee81ad5d8d7 | Hash listed for ccs.exe, identified as Betruger. |
| SHA1 | d15d45d9d9a8ef7a9f048d74b386f620f3b82576 | Hash listed for the actor’s FS64.exe file-collection tool. |
| SHA1 | f24fc14f39c160b54dc3b2fbd1eba605ec0eb04f | Hash listed for malicious earthtime.exe. |
| SHA256 | 18f0898d595ec054d13b02915fb7d3636f65b8e53c0c66b3c7ee3b6fc37d3566 | Hash listed for netscan.exe used to scan the victim network. |
| SHA256 | 6f9326224e6047458e692cd27aeb1054b9381c67aaf2fe238dbebfbc916c4b33 | Hash listed for the SystemBC DLL, named wakewordengine.dll or conhost.dll. |
| SHA256 | a4bc6bebabb52ed9816987b77ebae6ef70e174533a643aea6265bdf1ed9b8952 | Hash listed for the suspicious vhd.dll loader. |
| SHA256 | a7240d8a7aee872c08b915a58976a1ddee2ff5a8a679f78ec1c7cf528f40deed | Hash listed for sh.exe, identified as a renamed SharpHound binary. |
| SHA256 | ae7c31d4547dd293ba3fd3982b715c65d731ee07a9c1cc402234d8705c01dfca | Hash listed for ccs.exe, identified as Betruger. |
| SHA256 | aeaf7cc7364a44b381af9f317fe6f78c2717217800b93bee8839ab3e56233254 | Hash listed for the deployed Grixba executable gt_net.exe. |
| SHA256 | bcff246f0739ed98f8aa615d256e7e00bc1cb24c8cabaea609b25c3f050c7805 | Hash listed for malicious earthtime.exe. |
| SHA256 | c92c158d7c37fea795114fa6491fe5f145ad2f8c08776b18ae79db811e8e36a3 | Hash listed for adfind.exe used in the intrusion. |
| SHA256 | e1521e077079032df974c7ae39e4737cdb4f05c6ded677ed5446167466eeb899 | Hash listed for the actor’s FS64.exe file-collection tool. |
| SHA256 | f8810179ab033a9b79cd7006c1a74fbcde6ed0451c92fbb8c7ce15b52499353a | Hash listed for the deployed Grixba executable grb_net.exe. |
MITRE ATT&CK
T1003.001 · LSASS MemoryThe Betruger backdoor accessed LSASS process memory to harvest credentials.T1003.006 · DCSyncThe actor performed DCSync against a domain controller using a privileged account.T1016 · System Network Configuration DiscoveryThe actor ran ipconfig and other commands to inspect network configuration.T1018 · Remote System DiscoveryGrixba and other discovery commands enumerated systems in the victim network.T1021.001 · Remote Desktop ProtocolThe actor used RDP to move from the beachhead to domain controllers and other servers.T1036 · MasqueradingMalicious executables impersonated EarthTime and carried metadata mimicking security products.T1046 · Network Service DiscoveryGrixba and NetScan scanned internal hosts and services.T1047 · Windows Management InstrumentationThe actor used Impacket’s wmiexec to run reconnaissance commands on a domain controller.T1048 · Exfiltration Over Alternative ProtocolThe actor used WinSCP to exfiltrate the archives to an external FTP server.T1055 · Process InjectionSectopRAT injected into MSBuild.exe, and ccs.exe later injected into numerous running processes.T1059.001 · PowerShellThe actor executed PowerShell for Veeam credential retrieval and Active Directory computer enumeration.T1059.003 · Windows Command ShellThe actor executed reconnaissance commands through cmd.exe, including remotely through wmiexec.T1069.001 · Local GroupsThe actor ran net localgroup during local discovery.T1069.002 · Domain GroupsThe actor ran net group "Domain Admins" /domain.T1070.006 · TimestompGT_NET.exe changed timestamps on its ExportData.db output, including setting a future date.T1083 · File and Directory DiscoveryThe actor inspected files on shared drives, including an insurance policy document, before archiving data.T1087.001 · Local AccountBetruger-spawned commands included net user for user enumeration.T1087.002 · Domain AccountThe actor used Active Directory queries and commands to enumerate domain users.T1090 · ProxySystemBC provided proxy access used for RDP connections into the victim network.T1098.007 · Additional Local or Domain GroupsThe actor added the newly created Admon account to the local Administrators group.T1119 · Automated CollectionThe actor used FS64.exe to automate collection of files from a remotely mounted share.T1127.001 · MSBuildThe SectopRAT execution chain injected malware into MSBuild.exe.T1136.001 · Local AccountThe actor created the local Admon account on the beachhead host.T1204.002 · Malicious FileA user executed the malicious EarthTime.exe file after downloading it.T1482 · Domain Trust DiscoveryThe actor ran nltest commands to examine domain trusts.T1547.001 · Registry Run Keys / Startup FolderA shortcut placed in the Startup folder launched the renamed malicious EarthTime executable at user logon.T1555 · Credentials from Password StoresA PowerShell script queried the VeeamBackup Credentials table and used Veeam’s ProtectedStorage class to decrypt passwords.T1560.001 · Archive via UtilityThe actor used WinRAR to archive selected file shares before exfiltration.T1562.001 · Disable or Modify ToolsThe actor modified Windows Defender policy registry keys in an attempt to disable multiple protections.T1569.002 · Service ExecutionThe actor used PsExec to run SystemBC with SYSTEM privileges on a domain controller.T1570 · Lateral Tool TransferThe actor deployed SystemBC across compromised servers during lateral movement.T1572 · Protocol TunnelingThe actor established a SystemBC tunnel to support access into the internal network.
People
Threat Actors
DragonForceRansomware operation whose leak site reportedly listed a company appearing in a prior NetScan output found during the intrusion; the report treats this as a connection rather than confirmed attribution.PlayRansomware group linked to Grixba tooling; the report treats this as one of several connections, not confirmed attribution of the intrusion to the group.RansomHubRansomware operation whose affiliates have been linked to Betruger; the report treats this as a connection rather than confirmed attribution.
Malware
ArechClient2Red Canary has previously observed this activity linked to the SecTopRAT/ArechClient2, a .NET RAT tool, which also inspired the following threat hunting query, which would detect this activity.BetrugerThe threat actor deployed multiple malware families, including SystemBC for proxy tunneling, and later Betruger backdoor for additional capabilities.GrixbaThey leveraged various tools such as AdFind, SharpHound, SoftPerfect NetScan, and GT_NET.exe (Grixba) to map out the environment and perform reconnaissance activities.SectopRATThe intrusion began when a user downloaded and executed a malicious file impersonating DeskSoft’s EarthTime application but instead dropped SectopRAT malware.SystemBCThe threat actor deployed multiple malware families, including SystemBC for proxy tunneling, and later Betruger backdoor for additional capabilities.
Vendors
DeskSoftThe intrusion began when a user downloaded and executed a malicious file impersonating DeskSoft’s EarthTime application but instead dropped SectopRAT malware.Microsoftactor used multiple defense evasion techniques, including process injection, timestomping, disabling Microsoft Defender’s protections, and deploying binaries with spoofed metadata to disguise themselves asVeeamOn a backup server, they executed a PowerShell script designed to retrieve Veeam credentials.
Products
EarthTimeThe intrusion began when a user downloaded and executed a malicious file impersonating DeskSoft’s EarthTime application but instead dropped SectopRAT malware.Microsoft DefenderWe also observed the threat actor attempting to disable Windows Defender’s security features by modifying critical registry keys on the domain controller and backup server.VeeamOn a backup server, they executed a PowerShell script designed to retrieve Veeam credentials.WinRARData collection and exfiltration were performed using WinRAR to compress targeted file shares containing sensitive business documents, which were then transferred via WinSCP to an FTP server hosted by a cloud providerWinSCPto compress targeted file shares containing sensitive business documents, which were then transferred via WinSCP to an FTP server hosted by a cloud provider in clear text.
Tools
AdFindThey leveraged various tools such as AdFind, SharpHound, SoftPerfect NetScan, and GT_NET.exe (Grixba) to map out the environment and perform reconnaissance activities.FS64.exeThe threat actor also deployed a tool named FS64.exe, a custom tool designed for automating file collection.ImpacketLateral movement was primarily accomplished through RDP connections, with additional use of Impacket’s wmiexec.PsExecThey then followed up by connecting to the domain controller over RDP with the built-in Administrator account and used PsExec to execute SystemBC with SYSTEM privileges on the host.SharpHoundThey leveraged various tools such as AdFind, SharpHound, SoftPerfect NetScan, and GT_NET.exe (Grixba) to map out the environment and perform reconnaissance activities.SoftPerfect Network ScannerThey leveraged various tools such as AdFind, SharpHound, SoftPerfect NetScan, and GT_NET.exe (Grixba) to map out the environment and perform reconnaissance activities.wmiexecLateral movement was primarily accomplished through RDP connections, with additional use of Impacket’s wmiexec.