Author Topic: IDP.HELU.MSEx4 - Fileless Malware  (Read 9752 times)

0 Members and 1 Guest are viewing this topic.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2780
  • Volunteer
Re: IDP.HELU.MSEx4 - Fileless Malware
« Reply #15 on: October 19, 2019, 11:47:56 PM »
Hello Oliv,

Unless I'm miss reading your autorun attachment, that's msiserver, not msiexec.

Please also follow the instructions found here >> https://forum.avast.com/index.php?topic=194892.0

*Volunteer*.
Tier I SOC Analyst; Threat Hunter; Digital Forensics (no cert); HTB Competitor; Pentester (no cert).

4th Year BCS Student.

Offline Oliv.C

  • Jr. Member
  • **
  • Posts: 24
Re: IDP.HELU.MSEx4 - Fileless Malware
« Reply #16 on: October 20, 2019, 06:10:56 PM »
Hello Michael,
Yes you're right it's msiserver but it is the only entry that mentions msiexec.exe in the image path.
Thank you for your advice, i enclosed the report from MBAM & Farbar.
i see Farbar shows a few entries with a warning...

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 826
Re: IDP.HELU.MSEx4 - Fileless Malware
« Reply #17 on: October 23, 2019, 07:48:38 PM »
Have you installed Ardamax keylogger?

Offline Oliv.C

  • Jr. Member
  • **
  • Posts: 24
Re: IDP.HELU.MSEx4 - Fileless Malware
« Reply #18 on: October 24, 2019, 09:19:26 AM »
Hello Sass Drake, yep a while ago, but i uninstalled it since

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 826
Re: IDP.HELU.MSEx4 - Fileless Malware
« Reply #19 on: October 24, 2019, 06:51:19 PM »
OK and thank you for sharing screenshot of Task Manager. Let's now generate new FRST.txt and Addition.txt but this time in FRST.exe under Whitelist section uncheck: Registry, Processes, Services, Internet and Drivers.

Offline Oliv.C

  • Jr. Member
  • **
  • Posts: 24
Re: IDP.HELU.MSEx4 - Fileless Malware
« Reply #20 on: October 25, 2019, 10:48:40 AM »
Hello, and thanks for your help.
Here are the new logs.
thanks!

Offline PDI

  • Avast team
  • Full Member
  • *
  • Posts: 118
Re: IDP.HELU.MSEx4 - Fileless Malware
« Reply #21 on: October 25, 2019, 01:07:09 PM »
Hi,

I dug into the way how the MSIExec is executed and it have to be part of some task.

Your FIRST report shows "Task: {C7513494-BDD0-4427-8D9A-8C53723358EF} - \Thtise -> Pas de fichier <==== ATTENTION".
Could you check this record in the autoruns?

Regards,
PDI



Offline Oliv.C

  • Jr. Member
  • **
  • Posts: 24
Re: IDP.HELU.MSEx4 - Fileless Malware
« Reply #22 on: October 25, 2019, 03:12:22 PM »
Hello PDI, thanks for helping :)
Unfortunately i did not find any trace in Autoruns related to some "Thtise" or "8C53723358EF" entry...
maybe i can enclose the saved file from Autoruns if that helps.

I did find entries in regedit however
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache
under 2 different folders "Tasks", "Tree"
Not sure this helps... i have no idea what this file is
Thanks

Offline PDI

  • Avast team
  • Full Member
  • *
  • Posts: 118
Re: IDP.HELU.MSEx4 - Fileless Malware
« Reply #23 on: October 25, 2019, 03:51:20 PM »
Hi,

maybe you can try to create a support package (https://support.avast.com/en-eu/article/Submit-support-file) and post the ID here.

I'll look later on the result of it.

The content of the registry records can help too.

Regards,
PDI

Offline Oliv.C

  • Jr. Member
  • **
  • Posts: 24
Re: IDP.HELU.MSEx4 - Fileless Malware
« Reply #24 on: October 25, 2019, 06:05:43 PM »
Thanks,
so i did the support procedure.
The ID for my support file is WR90I
thank you

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 826
Re: IDP.HELU.MSEx4 - Fileless Malware
« Reply #25 on: October 25, 2019, 07:50:22 PM »
In meantime, please do this:

  • Open Notepad (click Start button -> type notepad.exe -> press Enter)
  • Copy text from code block below and paste it into Notepad
Code: [Select]
cmd: reg EXPORT "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msiserver" reg EXPORT HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msiserver "%userprofile%\Desktop\msiserver.txt"
cmd: type "%userprofile%\Desktop\msiserver.txt"
  • Go to File -> Save As
  • Make sure that  UTF-8 is selected as Encoding (left side of Save button)
  • Save it as fixlist.txt on Desktop
  • Open again FRST and click on button Fix
  • Wait until FRST finishes
  • fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.

Offline Oliv.C

  • Jr. Member
  • **
  • Posts: 24
Re: IDP.HELU.MSEx4 - Fileless Malware
« Reply #26 on: October 27, 2019, 01:18:33 PM »
Hello,
here is the fixlog
thanks

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 826
Re: IDP.HELU.MSEx4 - Fileless Malware
« Reply #27 on: October 27, 2019, 07:03:25 PM »
I'm sorry. I made a mistake in script. Please now do this:

  • Open Notepad (click Start button -> type notepad.exe -> press Enter)
  • Copy text from code block below and paste it into Notepad
Code: [Select]
cmd: reg EXPORT "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\msiserver" "%userprofile%\Desktop\msiserver.txt"
cmd: type "%userprofile%\Desktop\msiserver.txt"
  • Go to File -> Save As
  • Make sure that  UTF-8 is selected as Encoding (left side of Save button)
  • Save it as fixlist.txt on Desktop
  • Open again FRST and click on button Fix
  • Wait until FRST finishes
  • fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.

Offline Oliv.C

  • Jr. Member
  • **
  • Posts: 24
Re: IDP.HELU.MSEx4 - Fileless Malware
« Reply #28 on: October 27, 2019, 10:20:08 PM »
okay no problem
i ran it and this time it generated a fixlog and another file msiserver.txt

Offline Sass Drake

  • MyCity AMF R2
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 826
Re: IDP.HELU.MSEx4 - Fileless Malware
« Reply #29 on: October 28, 2019, 07:14:13 PM »
msiserver.txt hasn't provides us with useful clues. Let's now try this.

  • Open Notepad (click Start button -> type notepad.exe -> press Enter)
  • Copy text from code block below and paste it into Notepad
Code: [Select]
cmd: bitsadmin /list /verbose
  • Go to File -> Save As
  • Make sure that  UTF-8 is selected as Encoding (left side of Save button)
  • Save it as fixlist.txt on Desktop
  • Open again FRST and click on button Fix
  • Wait until FRST finishes
  • fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.