CYFIRMA analyzes a newly identified PowerShell-based keylogger that stealthily captures keystrokes and sensitive information from infected systems, leveraging cloud proxy and Onion/Tor-based C2 channels for anonymity. The report notes encoded command execution, screen capture, and an incomplete persistence mechanism, with a French-speaking developer indicated by script comments and persistent SOCKS proxy communications.
#PowerShell #Keylogger #Tor #Onion #SOCKSProxy #Finland #Oneprovider #French
#PowerShell #Keylogger #Tor #Onion #SOCKSProxy #Finland #Oneprovider #French
Keypoints
- PowerShell-based keylogger captures keystrokes and sensitive information.
- Command execution is performed via PowerShell without direct user interaction (Automation).
- System discovery includes file, directory, and system information gathering.
- Data exfiltration and C2 communications route through a cloud server in Finland and an Onion (Tor) service.
- Includes screen capture capability and Base64-encoded command execution for stealth.
- Persistent communication attempts via a SOCKS proxy are used to maintain connectivity.
MITRE Techniques
- [T1059.001] Command and Scripting Interpreter: PowerShell – “PowerShell process has been launched automatically in the background through a script, without any direct user input or interaction, indicating automated and potentially malicious activities being executed silently on the system.”
- [T1059] Command and Scripting Interpreter – “The Keylogger uses a Command and Scripting Interpreter technique to take command line arguments from the attacker to execute commands, scripts, or binaries.”
- [T1083] File and Directory Discovery – “It attempts to get the user’s profile directory, including application data on the system.”
- [T1082] System Information Discovery – “The keylogger gathers volume information (name, serial number, etc.) of the device and gathers information from crucial parts of the Windows Registry that contain settings and data related to the cryptographic operations of the system.”
- [T1571] Non-Standard Port – “Detected TCP or UDP traffic on non-standard ports where the attacker communicates using a protocol and port pairing that are typically not associated.”
Indicators of Compromise
- [IP] Proxy Server IP – 37.143.129.165
- [Domain] Onion C2 – opioem3zmp3bgx3qjqkh6vimkdoerrwh3uhawklm5ndv5e7k3t4edbqd.onion
- [Hash] SHA-256 – 181fe99c16fa6cc87a3161bc08a9e2dbd17531c7d713b09d8567c1b3debe121f
- [Hash] MD5 – b5e19d28e81e69edb9b2fbee7c4d57ad
- [File] File Name – 37-143-129-165.ps1
Read more: https://www.cyfirma.com/research/cyfirma-research-powershell-keylogger/