{"id":3228,"date":"2015-09-12T11:32:40","date_gmt":"2015-09-12T11:32:40","guid":{"rendered":"http:\/\/www.hexacorn.com\/blog\/?p=3228"},"modified":"2018-12-25T00:38:06","modified_gmt":"2018-12-25T00:38:06","slug":"beyond-good-ol-run-key-part-32","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2015\/09\/12\/beyond-good-ol-run-key-part-32\/","title":{"rendered":"Beyond good ol\u2019 Run key, Part 32"},"content":{"rendered":"<p><strong>Updated 2018-12-15<\/strong><\/p>\n<p>Here are some more persistence tricks combined into a single post. I normally don&#8217;t post links, but sometimes it really makes sense and here is one of such cases. The below is a list of links covering many interesting persistence mechanisms that popped up on my radar and I don&#8217;t want to write about them in separate blog entries as others already did a great job researching and covering them &#8211; lots of very interesting concepts covered here:<\/p>\n<ul>\n<li>Windows Platform Binary Table (very clever persistence mechanism used by Lenovo and HP)\n<ul>\n<li><a href=\"http:\/\/seclists.org\/bugtraq\/2015\/Aug\/44\">http:\/\/seclists.org\/bugtraq\/2015\/Aug\/44<\/a><\/li>\n<li><a href=\"http:\/\/download.microsoft.com\/download\/8\/A\/2\/8A2FB72D-9B96-4E2D-A559-4A27CF905A80\/windows-platform-binary-table.docx\">http:\/\/download.microsoft.com\/download\/8\/A\/2\/8A2FB72D-9B96-4E2D-A559-4A27CF905A80\/windows-platform-binary-table.docx<\/a><\/li>\n<li><a href=\"http:\/\/alex-ionescu.com\/Publications\/SyScan\/syscan2012.pdf\">http:\/\/alex-ionescu.com\/Publications\/SyScan\/syscan2012.pdf<\/a><\/li>\n<\/ul>\n<\/li>\n<li>Phantom DLL loading &#8211; MSDTC\/oci.dll\n<ul>\n<li><a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2012\/08\/hikit-rootkit-advanced-persistent-attack-techniques-part-1.html\">https:\/\/www.fireeye.com\/blog\/threat-research\/2012\/08\/hikit-rootkit-advanced-persistent-attack-techniques-part-1.html<\/a><\/li>\n<li><a href=\"http:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/shadow-force-uses-dll-hijacking-targets-south-korean-company\">http:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/shadow-force-uses-dll-hijacking-targets-south-korean-company<\/a><\/li>\n<\/ul>\n<\/li>\n<li>BIOS Computrace persistence mechanism\n<ul>\n<li><a href=\"https:\/\/securelist.com\/analysis\/publications\/58278\/absolute-computrace-revisited\/\">https:\/\/securelist.com\/analysis\/publications\/58278\/absolute-computrace-revisited\/<\/a><\/li>\n<li><a href=\"http:\/\/bartblaze.blogspot.com\/2014\/11\/thoughts-on-absolute-computrace.html\">http:\/\/bartblaze.blogspot.com\/2014\/11\/thoughts-on-absolute-computrace.html<\/a><\/li>\n<\/ul>\n<\/li>\n<li>File modification a.k.a. trojanizing (typically system) binaries (patching of the import table to add extra DLL)\n<ul>\n<li><a href=\"http:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/attack-gains-foothold-against-east-asian-government-through-auto-start\/\">http:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/attack-gains-foothold-against-east-asian-government-through-auto-start\/<\/a><\/li>\n<\/ul>\n<\/li>\n<li>Windows 8 lsasrv.dll allows you to load some arbitrary .dll inside lsass process\n<ul>\n<li><a href=\"http:\/\/redplait.blogspot.com\/2015\/02\/lsasrvdlllsaploadlsadbextensiondll.html\">http:\/\/redplait.blogspot.com\/2015\/02\/lsasrvdlllsaploadlsadbextensiondll.html<\/a>\u00a0(this is a very good reversing blog and worth following it)<\/li>\n<\/ul>\n<\/li>\n<li>IME keylogging can be implemented via intercepting IME layouts; persistence is achieved on the way\n<ul>\n<li><a href=\"https:\/\/www.symantec.com\/avcenter\/reference\/ime.as.a.possible.keylogger.pdf\">IME as a Possible Keylogger<\/a> [PDF warning]<\/li>\n<\/ul>\n<\/li>\n<li>WMI persistence (also including persistence using Managed Object Format (MOF))<br \/>\n&#8211; the below is a list of WMI-related documents that are a must-read &amp; cover persistence as well<\/p>\n<ul>\n<li><a href=\"http:\/\/la.trendmicro.com\/media\/misc\/understanding-wmi-malware-research-paper-en.pdf\">http:\/\/la.trendmicro.com\/media\/misc\/understanding-wmi-malware-research-paper-en.pdf<\/a><\/li>\n<li><a href=\"http:\/\/2014.hackitoergosum.org\/slides\/day1_WMI_Shell_Andrei_Dumitrescu.pdf\">http:\/\/2014.hackitoergosum.org\/slides\/day1_WMI_Shell_Andrei_Dumitrescu.pdf<\/a><\/li>\n<li><a href=\"https:\/\/dl.mandiant.com\/EE\/library\/MIRcon2014\/MIRcon_2014_IR_Track_There's_Something_About_WMI.pdf\">https:\/\/dl.mandiant.com\/EE\/library\/MIRcon2014\/MIRcon_2014_IR_Track_There&#8217;s_Something_About_WMI.pdf<\/a><\/li>\n<li><a href=\"https:\/\/media.defcon.org\/DEF%20CON%2023\/DEF%20CON%2023%20presentations\/Matt%20Graeber%20&amp;%20Willi%20Ballenthin%20&amp;%20Claudio%20Teodorescu\/DEFCON-23-Ballenthin-Graeber-Teodorescu-WMI-Attacks-Defense-.pdf\">https:\/\/media.defcon.org\/DEF%20CON%2023\/DEF%20CON%2023%20presentations\/Matt%20Graeber%20&amp;%20Willi%20Ballenthin%20&amp;%20Claudio%20Teodorescu\/DEFCON-23-Ballenthin-Graeber-Teodorescu-WMI-Attacks-Defense-.pdf<\/a><\/li>\n<li><a href=\"https:\/\/www.blackhat.com\/docs\/us-15\/materials\/us-15-Graeber-Abusing-Windows-Management-Instrumentation-WMI-To-Build-A-Persistent%20Asynchronous-And-Fileless-Backdoor-wp.pdf\">https:\/\/www.blackhat.com\/docs\/us-15\/materials\/us-15-Graeber-Abusing-Windows-Management-Instrumentation-WMI-To-Build-A-Persistent%20Asynchronous-And-Fileless-Backdoor-wp.pdf<\/a><\/li>\n<li><a href=\"https:\/\/www.fireeye.com\/content\/dam\/fireeye-www\/global\/en\/current-threats\/pdfs\/wp-windows-management-instrumentation.pdf\">https:\/\/www.fireeye.com\/content\/dam\/fireeye-www\/global\/en\/current-threats\/pdfs\/wp-windows-management-instrumentation.pdf<\/a><\/li>\n<li><a href=\"https:\/\/github.com\/fireeye\/flare-wmi\">https:\/\/github.com\/fireeye\/flare-wmi<\/a><\/li>\n<li><a href=\"https:\/\/msdn.microsoft.com\/en-us\/library\/aa823192%28v=vs.85%29.aspx\">https:\/\/msdn.microsoft.com\/en-us\/library\/aa823192%28v=vs.85%29.aspx<\/a><\/li>\n<li><a href=\"http:\/\/www.codeproject.com\/Articles\/28226\/Creating-WMI-Permanent-Event-Subscriptions-Using-M\">http:\/\/www.codeproject.com\/Articles\/28226\/Creating-WMI-Permanent-Event-Subscriptions-Using-M<\/a><\/li>\n<li><a href=\"http:\/\/poppopret.blogspot.com\/2011\/09\/playing-with-mof-files-on-windows-for.html\">http:\/\/poppopret.blogspot.com\/2011\/09\/playing-with-mof-files-on-windows-for.html<\/a><\/li>\n<li><a href=\"https:\/\/khr0x40sh.wordpress.com\/2014\/06\/10\/moftastic_powershell\/\">https:\/\/khr0x40sh.wordpress.com\/2014\/06\/10\/moftastic_powershell\/<\/a><\/li>\n<li><a href=\"https:\/\/khr0x40sh.wordpress.com\/2015\/01\/13\/meterpreter-post-module-persistence-via-mofpowershell\/\">https:\/\/khr0x40sh.wordpress.com\/2015\/01\/13\/meterpreter-post-module-persistence-via-mofpowershell\/<\/a><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li>COM Object hijacking (persistence mechanisms discussed on this blog previously but here are good examples of it being used by the actual malware)\n<ul>\n<li><a href=\"https:\/\/blog.gdatasoftware.com\/blog\/article\/com-object-hijacking-the-discreet-way-of-persistence.html\">https:\/\/blog.gdatasoftware.com\/blog\/article\/com-object-hijacking-the-discreet-way-of-persistence.html<\/a><\/li>\n<li><a href=\"http:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/poweliks-levels-up-with-new-autostart-mechanism\/\">http:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/poweliks-levels-up-with-new-autostart-mechanism\/<\/a><\/li>\n<\/ul>\n<\/li>\n<li>Persistence via Application Compatibility Database (SDB) (Application Compatibility fixes (Fix It Patches) \/ Shim Database \/ Hot Patching persistence)\n<ul>\n<li><a href=\"https:\/\/www.blackhat.com\/docs\/asia-14\/materials\/Erickson\/WP-Asia-14-Erickson-Persist-It-Using-And-Abusing-Microsofts-Fix-It-Patches.pdf\">https:\/\/www.blackhat.com\/docs\/asia-14\/materials\/Erickson\/WP-Asia-14-Erickson-Persist-It-Using-And-Abusing-Microsofts-Fix-It-Patches.pdf<\/a><\/li>\n<li><a href=\"https:\/\/www.youtube.com\/watch?v=SVqiDdVS7Wo\">https:\/\/www.youtube.com\/watch?v=SVqiDdVS7Wo<\/a><\/li>\n<\/ul>\n<\/li>\n<li>Not really a persistence mechanism, but the write-up for malware that establishes persistence only during the system shutdown\/reboot events\n<ul>\n<li><a href=\"http:\/\/labs.bitdefender.com\/2015\/08\/dridex-now-targets-romania-revives-word-macro-infection-technique\/\">http:\/\/labs.bitdefender.com\/2015\/08\/dridex-now-targets-romania-revives-word-macro-infection-technique\/<\/a><\/li>\n<\/ul>\n<\/li>\n<li>Using Windows Script Host to maintain persistence by launching Java Script\n<ul>\n<li><a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2014\/02\/ground-windows-scripting-host-wsh.html\">https:\/\/www.fireeye.com\/blog\/threat-research\/2014\/02\/ground-windows-scripting-host-wsh.html<\/a><\/li>\n<\/ul>\n<\/li>\n<li>Persistence via Language Bar Add-in (Microsoft\\CTF\\LangBarAddin)\n<ul>\n<li><a href=\"http:\/\/forum.sysinternals.com\/autoruns-missing-dlls-loaded-with-langbaraddin-key_topic25190.html\">http:\/\/forum.sysinternals.com\/autoruns-missing-dlls-loaded-with-langbaraddin-key_topic25190.html<\/a><\/li>\n<li><a href=\"https:\/\/www.fireeye.com\/blog\/threat-research\/2013\/02\/its-a-kind-of-magic-1.html\">https:\/\/www.fireeye.com\/blog\/threat-research\/2013\/02\/its-a-kind-of-magic-1.html<\/a><\/li>\n<\/ul>\n<\/li>\n<li>Persistence Through Shell Extension Handlers\n<ul>\n<li><a href=\"http:\/\/herrcore.blogspot.com.tr\/2015\/06\/malware-persistence-with.html\">http:\/\/herrcore.blogspot.com.tr\/2015\/06\/malware-persistence-with.html<\/a><\/li>\n<\/ul>\n<\/li>\n<li>Very good list of persistence mechanisms\n<ul>\n<li><a href=\"http:\/\/jumpespjump.blogspot.com\/2015\/05\/many-ways-of-malware-persistence-that.html\">http:\/\/jumpespjump.blogspot.com\/2015\/05\/many-ways-of-malware-persistence-that.html<\/a><\/li>\n<\/ul>\n<\/li>\n<li>Totally not Windows-related, but very interesting extension of the whole &#8216;collect all autorun entries&#8217; series &#8211; list of MAC OS\/X autostart entries\n<ul>\n<li><a href=\"http:\/\/www.forensicartifacts.com\/2015\/08\/mac-os-x-autorun-locations\/\">http:\/\/www.forensicartifacts.com\/2015\/08\/mac-os-x-autorun-locations\/<\/a><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><strong>Update<\/strong><\/p>\n<p>After I posted this entry <a href=\"https:\/\/twitter.com\/real_redp\">redp<\/a> (author of <a href=\"http:\/\/redplait.blogspot.com\">http:\/\/redplait.blogspot.com<\/a> blog) pinged me (thanks!) to add one more item I missed:<\/p>\n<ul>\n<li>RPC Extensions<br \/>\nstarting with Windows 7 rpcrt4.dll and RpcEpMap.dll enumerate HKLM\\Software\\Microsoft\\Rpc\\Extensions and load them<\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li data-wpview-marker=\"http%3A%2F%2Fredplait.blogspot.ru%2F2011%2F04%2Frpc-extensions.html\"><a href=\"http:\/\/redplait.blogspot.ru\/2011\/04\/rpc-extensions.html\">http:\/\/redplait.blogspot.ru\/2011\/04\/rpc-extensions.html<\/a><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li data-wpview-marker=\"http%3A%2F%2Fredplait.blogspot.ru%2F2011%2F04%2Frpc-extensions.html\"><a href=\"http:\/\/forum.sysinternals.com\/rpc-extensions_topic25896.html\">http:\/\/forum.sysinternals.com\/rpc-extensions_topic25896.html<\/a><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><strong>Update 2016<br \/>\n<\/strong><\/p>\n<p>One more entry from the Adapt Forward web site:<\/p>\n<ul>\n<li>Netshell helper DLLs\n<ul>\n<li><a href=\"http:\/\/www.adaptforward.com\/2016\/09\/using-netshell-to-execute-evil-dlls-and-persist-on-a-host\/\">http:\/\/www.adaptforward.com\/2016\/09\/using-netshell-to-execute-evil-dlls-and-persist-on-a-host\/<\/a><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><strong>Update 2017<\/strong><\/p>\n<ul>\n<li>Turns out the Netshell helper DLLs have been already discussed online in <a href=\"https:\/\/blogs.msdn.microsoft.com\/oldnewthing\/20101111-00\/?p=12303\">2010<\/a> and <a href=\"http:\/\/seclists.org\/fulldisclosure\/2013\/Jun\/123\">2013<\/a> (Thx Stefan K.)<\/li>\n<\/ul>\n<p><strong>Update 2017 #2<\/strong><\/p>\n<ul>\n<li>Persistence via Outlook\n<ul>\n<li><a href=\"https:\/\/enigma0x3.net\/2014\/10\/14\/persistence-using-microsoft-outlook\/\">https:\/\/enigma0x3.net\/2014\/10\/14\/persistence-using-microsoft-outlook\/<\/a><\/li>\n<\/ul>\n<\/li>\n<li>Persistence via Microsoft Add-ins\n<ul>\n<li><a href=\"https:\/\/labs.mwrinfosecurity.com\/blog\/add-in-opportunities-for-office-persistence\/\">https:\/\/labs.mwrinfosecurity.com\/blog\/add-in-opportunities-for-office-persistence\/<\/a><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><strong>Update 2017 #3<\/strong><\/p>\n<ul>\n<li>Persistence via Bitsadmin &#8211; this is a very creative and not well-known! Thx <a href=\"https:\/\/twitter.com\/3gstudent\">3gstudent\u00a0<\/a>\u00a0&#8211; I got so interested that described it <a href=\"https:\/\/www.hexacorn.com\/blog\/2017\/07\/12\/beyond-good-ol-run-key-part-64\/\">here<\/a>\n<ul>\n<li><a href=\"https:\/\/github.com\/3gstudent\/bitsadminexec\">https:\/\/github.com\/3gstudent\/bitsadminexec<\/a><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Updated 2018-12-15 Here are some more persistence tricks combined into a single post. I normally don&#8217;t post links, but sometimes it really makes sense and here is one of such cases. The below is a list of links covering many &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2015\/09\/12\/beyond-good-ol-run-key-part-32\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[13,35,15,19,9],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/3228"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=3228"}],"version-history":[{"count":14,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/3228\/revisions"}],"predecessor-version":[{"id":5736,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/3228\/revisions\/5736"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=3228"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=3228"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=3228"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}