A loader chain starting from a ClickFix lure abuses signed IBM SPSS IDE, decoy DLLs, and EnumTimeFormatsEx to deliver the BabaDeda stage and the CNCMachineRMS remote administration implant. CNCMachineRMS uses custom scripting, a unified config/C2 container, and multiple stealth features to provide shell access, file management, screen capture, persistence, and local account backdoor capabilities. #ClickFix #IBMSPSSIDE #WinWrapIDE #BabaDeda #CNCMachineRMS
Keypoints
- The infection starts with a ClickFix lure and eventually launches the legitimately signed IBM SPSS IDE binary, WinWrapIDE.exe.
- A chain of four decoy DLLs is used to reach shellcode without suspicious direct API calls or obvious loading behavior.
- The final decoy uses EnumTimeFormatsEx as a benign trampoline to execute shellcode indirectly.
- The shellcode stage, called BabaDeda, depends on a separate obfuscated config file named HelperStandardizationApplication.bin.
- The embedded payload is CNCMachineRMS, a 1.14 MB x64 implant built for remote administration rather than simple payload delivery.
- CNCMachineRMS includes interactive shell access, file management, screen capture, local account backdoor creation, seven persistence mechanisms, and 20 typed commands.
- The malware uses its own scripting language and a shared serialized container format for config, local state, and C2 traffic, with the campaign associated with ânovm.â
MITRE Techniques
- [T1218.009 ] Signed Binary Proxy Execution: WinRAR/Self-Extracting Archives â Abusing a legitimately signed IBM SPSS IDE binary to activate the attack chain (âa legitimately signed IBM SPSS IDE, WinWrapIDE.exe, is launchedâ).
- [T1055 ] Process Injection â Shellcode is written into memory and executed in-process through a benign callback path (âwrites shellcode into the middle of it, and marks it executableâ).
- [T1202 ] Indirect Command Execution â The malware is triggered through EnumTimeFormatsEx instead of a direct malicious call path (âWindows calls the malware on the attackerâs behalfâ).
- [T1027 ] Obfuscated Files or Information â The config, state database, and payload use layered obfuscation and high-entropy random-looking data (âlooks like an encrypted blobâ, âunder two layers of obfuscationâ).
- [T1027.002 ] Software Packing â The embedded payload and config are concealed in packed/serialized containers rather than plain binary structures (âthe config and its command and control (C2) traffic travel in the same custom binary containerâ).
- [T1059 ] Command and Scripting Interpreter â The implant runs behavior through its own custom scripting language (âdriven by a custom scripting language the author wroteâ).
- [T1105 ] Ingress Tool Transfer â The operator can stage and run additional payloads through typed commands (âtwenty typed commands for pulling down and running further payloadsâ).
- [T1068 ] Exploitation for Privilege Escalation â The implant creates local accounts and adds them to privileged groups (âIt creates local accounts and adds them to privileged groupsâ).
- [T1547.001 ] Registry Run Keys / Startup Folder â Persistence via a Run key is explicitly described (âA Run key or scheduled task named IBM SPSS WinWrap Basic IDEâ).
- [T1053.005 ] Scheduled Task/Job: Scheduled Task â Persistence is also established with scheduled tasks (âScheduled tasks created with /SC ONLOGON /RU SYSTEM /F /RL HIGHESTâ).
- [T1010 ] Application Window Discovery â A screenshot is taken on first contact, indicating host interaction and reconnaissance (âIt takes a screenshot on first contactâ).
- [T1087.001 ] Account Discovery: Local Account â The host profile and backdoor actions involve local account context (âDomain, SID, and elevation statusâ, âCreates local accountsâ).
Indicators of Compromise
- [Domain / IP] C2 and network beaconing â Notepadreleased[.]com, 85[.]158.110.78
- [DNS-over-HTTPS endpoints] DNS resolution path used by the implant â dns.google, cloudflare-dns.com, dns.quad9.net
- [File path] Task payload dropped under TEMP â %TEMP%CNCMachineRMStasks*task_payload.bin
- [File path] Local state database â %LOCALAPPDATA%SProjectsp.bin
- [File path] VM check trigger artifact â C:Intel directory
- [Registry / task name] Persistence artifact â IBM SPSS WinWrap Basic IDE
- [Windows Event IDs] Local account backdoor activity â 4720, 4732
- [SHA256] Signed loader and DLLs â 0562c588997fa9961d55c6ab1db2656344324bca8db9ea7b64fe309132b2399f, 5b71b49bad415643ff3e291ee3ba550e5edfd584eb913859dadb81634450e7e7
- [SHA256] Additional payload components â 3d4e7187f74de912f9d52f5ba6a95bd41868348b16583d72957d732c0ed8f0e7, b804b9dd2726e69fb4f496a6872f90edf9146ad8044c6d3a592040ce1074a5d0, and other 5 hashes
- [SHA256] Memory-only stages â 744b8165b6161cbd1d5ecc423ecfdb8306485afdc80262000ab3c6908881ef9e, bb81786286be437b3ec6d562055767097c9277054e1d09172caa96376451481c