Microsoft Store Apps + Go Backconnect Proxyware Part 2


I've observed some new stores and updated campaign behavior related to what I wrote about in Part 1. Some changes include the Store publisher names, DLL file names, and a move from koffi to ffi-rs for the loading of the Go based proxyware binary.

A detailed writeup on some of the new behaviors can be seen from HexaStrike who has named this campaign StoreSocks. I kind of like the name. Anyway, I don't intend this to be a long post, just some quick updates and observations on the campaign.

New Publisher Names

  • TECHNOLOGIES FOR BUSINESS LLC
  • SOFTWARE MATTERS LLC
App Store Publisher Software Matters LLC

technologies for business llc on App Store


New DLL file names:

  • telemetry.dll
  • /lib[A-Z0-9]{3}\.dll/
VirusTotal YARA hits for Go Proxyware DLLs

New C2:

  • gate1.storetelemetryapiapps.xyz
  • telemetrystoreapi1.xyz
  • storetelemetryapi.xyz
Local Listener Results for Proxyware running in VM


Additional Reading on recent Proxyware News:

Detection


DLL Files and Hashes

The following table contains SHA-256 hashes associated with DLL payloads observed during this campaign. Because the campaign continues to change, the most current list is maintained in the SecurityMagic StoreSocks IOC repository .

DLL / Package Path SHA-256
app/libHA5.dll f08cd56084e29b4039c39dff23dc52ee1eccd24236f38fbcd70e8dbf4bdb13da
libSJ2.dll 386c57c9a8290c333d5c55ea4736fa47034354ecf63b8aa194fb623b43a1fb29
telemetry.dll 8b42829ba1f8afb58c5639e10a8b7ae74690086e8aa8ca78290c10957895b423
lib3Z7.dll be432e17d1f55aa0860a92864b195cac3aa13cdd730f87a202670af048cc4455
app/telemetry.dll d899433ce1ac329c491ccb04c8ddaa1ff911d06ffc2bb0a17025edda53210219
app/lib95S.dll 14792371ad9d1648ab4bed17550be9642f1ee20a2c1b0062f080acfcbb65db59
app/client.dll 27870854b9e85265e21d06a4b9e696093c1558c1480e36a42540943d66f7a3ec
telemetry_pdx.dll e92bcbd4df92eef112b3c216af0ada724f73fb9b59a632602611b5690a24e407
lib37Q.dll c7103f1ddcbc3d27fc1e618a8b15e7a7d021d9d2d14c7f5f95c4c23c741ec1f7
app/lib95S.dll 6cfde3902819836bb2040e7f9e5a573e099c4c09f20ce9c0b64f5866d38b7bbd
app/libHA5.dll 7b6ae71eabef3ed508e44d263c0ae5674e16c1a4a103905e7b82ed184a3b3f4d
libHA5.dll 3d3802acc04fd60e5fee99236438c689e9ae6844fb87095bf7a10face750f98f
libJBR.dll 1380cfcab1bd9dee1048ddc30bc7d7b061c80e2790a18c7e163c72005cc40dd8
app/client.dll c2811de09557c481a05b42b681ecc612f5d4c95543e25c9012061fb134c88d9e
app/client.dll 6af8931615475941b797f9a4a2f2149c06502f52435bb307a7d7bbbdc6323abd
app/telemetry.dll a094293b06e43060eb93d31237a931d26756df18f7e0ec5f2b762d7672bb08c6
app/telemetry.dll 94182f6ad0ed5e1f02ffe646d5cef1ad161de43924656000478e1359de230438
VFS/ProgramFilesX64/Screen Recorder/Screen Recorder/monitor.dll 74c7ad2e218a3cdabd326e3c7940c64657b847a8b2bc7beaa2d417d60eba659f
app/telemetry.dll c1a4260f50a853732d23960d6c20cebdb3b470feb253597a96a24b3855a5a593
app/lib95S.dll 99a76d3aeaaa4bae71906bffc0b41e59234aa7a6879cf14b5e301c68213ae7f4
libSJ2.dll 25d6825b92738306842c5694dd7eceb739d8e40a5c933fe807b6d311b2ebc470
client.dll 42b989fb7b81ac22c91ceb8022e21805acd949b6f0cec36a9ad72496f4fae791
backconnect_prod.dll f61252203cc8b3ea93354c252e22b4ec8e5e1d6e7d3cac11bef64dfb7deddf3e
2c253d8131cf8a948115884467aeeba28f43a85a289b730b5e490fb59ad4c921.dll 2c253d8131cf8a948115884467aeeba28f43a85a289b730b5e490fb59ad4c921
app/client.dll 09049e365c86e0bc6192fb1601d0fbe6bf2235f9f3e26ea1c83e26f41d041530
VFS/ProgramFilesX64/Screen Recorder Free - Screen Record & Screen Capture/Screen Recorder Free - Screen Record & Screen Capture/monitor.dll ebec28fd7ced06e42a94319418f01fb7dc3f60a1e21821ef41d259d5ad3f2b03
client.dll bc2ea22be1b6e77a4c15350f5a9c049d9d84505c64941e65e8191db4d0fbd7e4

Final Thoughts:

This appears to be the same campaign, just updated with slightly new techniques and new publisher names. 

I have not seen any disclosure that installing their App would subject the end user to volunteering to be part of a residential proxy network, if I missed seeing any notification, please let me know, otherwise, this appears to be deceptive, luring users into installing "free" software, but unknowingly offering their host as a proxy for others to use. 

With recent news trends on TVs being part of proxy network which was abused by threat actors, it becomes increasingly important to be aware of proxyware. While these may not inherently have malicious intent, users of the service that "browse" through you home IP, may do something nefarious or illegal that may be tracked back to your home.


Comments

Popular posts from this blog

Beware of Fake 7zip Installer: upStage Proxy

Microsoft Store Apps May Deliver Go Backconnect Proxy Malware

New HydraSeven malware loader found in the wild