Microsoft Store Apps + Go Backconnect Proxyware Part 2
A detailed writeup on some of the new behaviors can be seen from HexaStrike who has named this campaign StoreSocks. I kind of like the name. Anyway, I don't intend this to be a long post, just some quick updates and observations on the campaign.
New Publisher Names
New DLL file names:
- gate1.storetelemetryapiapps.xyz
- telemetrystoreapi1.xyz
- storetelemetryapi.xyz
Additional Reading on recent Proxyware News:
- Nearly half of Smart TVs with Proxyware
- FBI Seizes NetNut Proxy Platform, Popa Botnet
- STORESOCKS – Microsoft Store Apps Deliver a Go Backconnect Proxy
- Microsoft Store Apps May Deliver Go Backconnect Proxy Malware Part 1
- Lurking Lizard distributes fake 7-zip and other applications to deploy proxyware
- Inside the Search for "Clean" Residential Proxies for Carding
Detection
- SecurityMagic Github YARA
- Watch for unfamiliar dll file names in WindowsApps Directory
DLL Files and Hashes
The following table contains SHA-256 hashes associated with DLL payloads observed during this campaign. Because the campaign continues to change, the most current list is maintained in the SecurityMagic StoreSocks IOC repository .
| DLL / Package Path | SHA-256 |
|---|---|
app/libHA5.dll |
f08cd56084e29b4039c39dff23dc52ee1eccd24236f38fbcd70e8dbf4bdb13da |
libSJ2.dll |
386c57c9a8290c333d5c55ea4736fa47034354ecf63b8aa194fb623b43a1fb29 |
telemetry.dll |
8b42829ba1f8afb58c5639e10a8b7ae74690086e8aa8ca78290c10957895b423 |
lib3Z7.dll |
be432e17d1f55aa0860a92864b195cac3aa13cdd730f87a202670af048cc4455 |
app/telemetry.dll |
d899433ce1ac329c491ccb04c8ddaa1ff911d06ffc2bb0a17025edda53210219 |
app/lib95S.dll |
14792371ad9d1648ab4bed17550be9642f1ee20a2c1b0062f080acfcbb65db59 |
app/client.dll |
27870854b9e85265e21d06a4b9e696093c1558c1480e36a42540943d66f7a3ec |
telemetry_pdx.dll |
e92bcbd4df92eef112b3c216af0ada724f73fb9b59a632602611b5690a24e407 |
lib37Q.dll |
c7103f1ddcbc3d27fc1e618a8b15e7a7d021d9d2d14c7f5f95c4c23c741ec1f7 |
app/lib95S.dll |
6cfde3902819836bb2040e7f9e5a573e099c4c09f20ce9c0b64f5866d38b7bbd |
app/libHA5.dll |
7b6ae71eabef3ed508e44d263c0ae5674e16c1a4a103905e7b82ed184a3b3f4d |
libHA5.dll |
3d3802acc04fd60e5fee99236438c689e9ae6844fb87095bf7a10face750f98f |
libJBR.dll |
1380cfcab1bd9dee1048ddc30bc7d7b061c80e2790a18c7e163c72005cc40dd8 |
app/client.dll |
c2811de09557c481a05b42b681ecc612f5d4c95543e25c9012061fb134c88d9e |
app/client.dll |
6af8931615475941b797f9a4a2f2149c06502f52435bb307a7d7bbbdc6323abd |
app/telemetry.dll |
a094293b06e43060eb93d31237a931d26756df18f7e0ec5f2b762d7672bb08c6 |
app/telemetry.dll |
94182f6ad0ed5e1f02ffe646d5cef1ad161de43924656000478e1359de230438 |
VFS/ProgramFilesX64/Screen Recorder/Screen Recorder/monitor.dll |
74c7ad2e218a3cdabd326e3c7940c64657b847a8b2bc7beaa2d417d60eba659f |
app/telemetry.dll |
c1a4260f50a853732d23960d6c20cebdb3b470feb253597a96a24b3855a5a593 |
app/lib95S.dll |
99a76d3aeaaa4bae71906bffc0b41e59234aa7a6879cf14b5e301c68213ae7f4 |
libSJ2.dll |
25d6825b92738306842c5694dd7eceb739d8e40a5c933fe807b6d311b2ebc470 |
client.dll |
42b989fb7b81ac22c91ceb8022e21805acd949b6f0cec36a9ad72496f4fae791 |
backconnect_prod.dll |
f61252203cc8b3ea93354c252e22b4ec8e5e1d6e7d3cac11bef64dfb7deddf3e |
2c253d8131cf8a948115884467aeeba28f43a85a289b730b5e490fb59ad4c921.dll |
2c253d8131cf8a948115884467aeeba28f43a85a289b730b5e490fb59ad4c921 |
app/client.dll |
09049e365c86e0bc6192fb1601d0fbe6bf2235f9f3e26ea1c83e26f41d041530 |
VFS/ProgramFilesX64/Screen Recorder Free - Screen Record & Screen Capture/Screen Recorder Free - Screen Record & Screen Capture/monitor.dll |
ebec28fd7ced06e42a94319418f01fb7dc3f60a1e21821ef41d259d5ad3f2b03 |
client.dll |
bc2ea22be1b6e77a4c15350f5a9c049d9d84505c64941e65e8191db4d0fbd7e4 |
Final Thoughts:
This appears to be the same campaign, just updated with slightly new techniques and new publisher names.
I have not seen any disclosure that installing their App would subject the end user to volunteering to be part of a residential proxy network, if I missed seeing any notification, please let me know, otherwise, this appears to be deceptive, luring users into installing "free" software, but unknowingly offering their host as a proxy for others to use.
With recent news trends on TVs being part of proxy network which was abused by threat actors, it becomes increasingly important to be aware of proxyware. While these may not inherently have malicious intent, users of the service that "browse" through you home IP, may do something nefarious or illegal that may be tracked back to your home.




Comments
Post a Comment