Does anybody know how Emotet/Trickbot gets from a non-admin user to SYSTEM on Windows 7?
-
Show this thread
-
It's not credential misuse, they've actually injected into svchost on a reasonably patched Win7 box.
5 replies 3 retweets 28 likesShow this thread -
So I’m going to look into this more at the weekend, I’ve got a honeypot network called EmoPot (great name Kevin) which has gone Emotet to Trickbot, but they’re somehow injected into svchost.exe from normal userland, spitting out emails and such from it.
pic.twitter.com/IsaoFH02AF
7 replies 7 retweets 55 likesShow this thread -
So this turned out to be a really valuable thread, thank you
@neondhruv@XMPPwocky@jgajek and others for pointing at process hollowing direction as they're spot on. Two of the boxes are doing some weird things (Windows itself is unstable, e.g. can't even load Process Explorer).3 replies 1 retweet 10 likesShow this thread -
Replying to @GossiTheDog @neondhruv and
But process hollowing doesn't inherently allow for escalation from non-admin to SYSTEM, right? Am I missing something?
2 replies 0 retweets 4 likes -
Replying to @wdormann @GossiTheDog and
This is little more complicated than a simple process hollowing. Levergaes “double process hollowing” technique based on Windows Native API, leveraging the “svchost.exe” system process as a way to make privilege escalation & inject mal code . Sadly Win API poorly documented
1 reply 1 retweet 4 likes -
Replying to @neondhruv @wdormann and
Spent 4 hours searching github. Double process hollowing to priv esc is nowhere to be found. My OSCP exam is 3 weeks, so if you have working code remember sharing is caring.
#tistheseason2 replies 0 retweets 0 likes
I've seen no evidence that double process hollowing to priv esc is a thing. Only poorly-worded advisories that were likely parroted here. Were it a thing, and just how Windows is, then we can probably just forget about user accounts, security boundaries, and everything on Win.
-
-
I agree. Would look for another privilege escalation mechanism prior to the process hollowing.
0 replies 0 retweets 2 likesThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.