Counterfeit installers to system compromise: Tracking a deceptive software download campaign | Microsoft Security Blog
Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to distribute dynamically generated malicious installers. The campaign, attributed with moderate confidence to Silver Fox (Yinhu), targets Chinese-speaking users and China-based operations of multinational organizations. The attack chain involves dropping randomized payloads, establishing persistence via disguised scheduled tasks, escalating privileges using SYSTEM scheduled tasks, and employing defense evasion techniques such as adding Defender exclusions, deleting shadow copies, and disabling Windows Update.
- domainapp-microsoft-edge[.]com[.]cnSpoofed Microsoft Edge download site used as a lure.
- domainbaidu-pan[.]com[.]cnSpoofed Baidu Netdisk download site used as a lure.
- domainbxfh[.]tzcdq[.]cnDelivery host serving malicious installer archives.
- domaincalibre-ebook[.]com[.]cnSpoofed Calibre download site used as a lure.
- domaincc8ttkv35b[.]comDelivery host serving malicious installer archives.
- domaincn-drawio[.]com[.]cnSpoofed draw.io download site used as a lure.
- domainczijbh[.]netSix-character .net domain used for command and control.
- domaineuioxu[.]netSix-character .net domain used for command and control.
- domaingehie246[.]comDelivery host serving malicious installer archives from spoofed vendor pages.
- domaingw-sogou[.]com[.]cnSpoofed Sogou download site used as a lure.
- domainiualef[.]netSix-character .net domain used for command and control.
- domainkaspersky-lab[.]hl[.]cnSpoofed Kaspersky download site used as a lure.
- domainmebx78e02[.]comDelivery host serving malicious installer archives.
- domainmindmoster[.]com[.]cnTyposquat domain impersonating MindMaster used as a lure.
- domainn7b8t85zsg[.]comDelivery host serving malicious installer archives.
- domainocam-pc[.]com[.]cnSpoofed oCam Screen Recorder download site used as a lure.
- domainoijfwe[.]netSix-character .net domain used for command and control.
- domainpc-razerzone[.]com[.]cnSpoofed Razer download site used as a lure to deliver malicious installers.
- domainqwjre1487[.]comDelivery host serving malicious installer archives.
- domainsejda[.]hl[.]cnSpoofed Sejda PDF download site used as a lure.
- domainsteelseries-cn[.]com[.]cnSpoofed SteelSeries download site used as a lure.
- domaintbdqxq[.]netSix-character .net domain used for command and control.
- domaintmsq[.]tzcdq[.]cnDelivery host serving malicious installer archives.
- domaintranslate-youdao[.]hl[.]cnSpoofed NetEase Youdao Dictionary download site used as a lure.
- domainwfmwsj[.]netSix-character .net domain used for command and control.
- domainyimxg25tiy[.]comDelivery host serving malicious installer archives.
- domainzh-diskgenius[.]com[.]cnSpoofed DiskGenius download site used as a lure.
- filenameC:\ProgramData\<random>\<random>.exeSystem location used for persistent payloads launched by scheduled tasks.
- filenameC:\ProgramFilesx86\72q1o6\XPSPLOG.dllMalicious DLL loaded by the later-stage payload for DLL side-loading.
- filenameC:\ProgramFilesx86\<random>\<random>.exeSystem location used for staging later-stage payloads.
- filenameC:\Users\Public\<random>\<random>.exeWorld-writable location used for dropping randomized stage-one payloads.
- ip103[.]156[.]25[.]35C2 endpoint observed on port 7031.
- ip103[.]183[.]3[.]162C2 endpoint associated with domain oijfwe.net on port 5090.
- ip161[.]248[.]87[.]157C2 IP endpoint.
- ip202[.]95[.]14[.]237Primary C2 hub IP observed on AS152194 (CTG Server Limited).
- ip43[.]99[.]100[.]248C2 IP endpoint.
- ip47[.]239[.]175[.]163C2 IP endpoint.
- ip47[.]239[.]232[.]245C2 endpoint observed communicating over port 8050.
- ip47[.]243[.]218[.]255C2 endpoint observed communicating over port 28300.
- ip47[.]86[.]205[.]97C2 IP endpoint.
- registry_keyHKLM\SOFTWARE\Microsoft\WindowsDefender\Exclusions\PathsRegistry key modified by the malware to add Defender exclusions.
- registry_keyHKLM\Software\Policies\Microsoft\Windows\WindowsUpdate\AURegistry key modified to set NoAutoUpdate and neutralize Windows Update.
- sha2561bd3662d784840e410d2d3c0a1040277f7f549089447359f01e05c2559cb1f17SHA256 hash of the persistent payload that performs process injection.
- sha256676a2a7b94ca2f8ec76352ee656e4d075bb342bd7ad6efbc7c19c060001eace7SHA256 hash of the stable stage-one payload dropped by the wrapper installer.
- sha2566d6ba2bc9ad414837826f7278bc3e0116f1aeda02d0c2284ed65819f5d9180a8SHA256 hash of the later-stage payload masquerading as Philips Speech Driver.
- sha256c4100ad39d8db98f063feb6c3b6c8e9a9f9d9bf25a1e0233f43b058ff8a7dbdfSHA256 hash of the networking payload.
- sha256c6100166e2d3b40388980f7674712ef39e937ac04925ca5d370415399ed73fafSHA256 hash of the persistent TrueUpdate loader payload.
- sha256e4fe2dee8f0bb132fa15fc686d1f93df39530a2d3a8d3a1f3a605a057c04e7b3SHA256 hash of a supporting DLL used in the campaign.
- sha256f33d160d757e4b39019fdef21cf90cafb501b800ca0d4039366bc30856e3d81bSHA256 hash of the persistent/networking payload.
- urlhxxps://upitem[.]oss-cn-hangzhou[.]aliyuncs[.]comAttacker-controlled Alibaba Cloud OSS bucket URL used for C2 over TLS.
- urlhxxps://www[.]gehie246[.]com/712downDelivery URL serving dynamically generated malicious ZIP archives.
- urlhxxp://www[.]gehie246[.]com/712downDelivery URL serving dynamically generated malicious ZIP archives.
Detection / Hunteropenrouter
What Happened
Attackers are setting up fake websites that look like legitimate software download pages to trick users into downloading malicious installers. Once installed, the malware hides itself by disabling security features and deleting recovery points, then stays on the computer by creating scheduled tasks that run repeatedly. The attackers can then control the compromised computer and potentially move to other computers on the same network. This primarily affects Chinese-speaking users and organizations with operations in China. To protect against this, organizations should ensure their security tools are enabled, prevent downloads from untrusted sources, and monitor for suspicious scheduled tasks and security software modifications.
Key Takeaways
- Active malware campaign uses counterfeit software-download websites to distribute dynamically generated malicious installers.
- Attack chain involves dropping randomized payloads, establishing persistence via disguised scheduled tasks, and escalating privileges using SYSTEM scheduled tasks.
- Defense evasion techniques include adding sweeping Microsoft Defender exclusions, deleting volume shadow copies, and neutralizing Windows Update services.
- Command and control is established over non-standard ports and abused cloud object storage services.
- Microsoft attributes this activity to the Silver Fox (Yinhu) campaign with moderate confidence.
Affected Systems
- Windows operating systems
- Microsoft Defender Antivirus
- Microsoft Edge
- Windows Installer (msiexec.exe)
- Windows Task Scheduler
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Users are lured to counterfeit software-download websites (e.g., pc-razerzone.com.cn) that spoof legitimate vendors.
- Delivery: The spoofed sites redirect users to dedicated delivery hosts (e.g., gehie246.com) which serve dynamically generated malicious ZIP archives.
- Execution: The archive contains a wrapper installer that drops a stage-one payload at a randomized path, or uses msiexec.exe in embedded mode to launch the payload.
- Persistence: The malware creates disguised scheduled tasks (e.g., 'Deadline Mission Target') that launch payloads from C:\ProgramData\ with a ~60-second re-execution cadence.
- Privilege Escalation: Short-lived scheduled tasks running as SYSTEM are created to perform privileged actions, such as writing Microsoft Defender exclusions.
- Defense Evasion: The malware adds sweeping Defender exclusions, deletes volume shadow copies, disables Windows Update services, and uses process injection and masquerading techniques.
- Command and Control: Payloads establish C2 over non-standard ports (e.g., 5090, 8050) and abused cloud object storage services.
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: Yes
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
- Platforms: Microsoft Defender XDR Advanced Hunting, Microsoft Sentinel
The article provides several KQL queries for Microsoft Defender XDR and Microsoft Sentinel to hunt for campaign payloads, randomized payload drop patterns, Defender exclusion tampering, recovery inhibition, msiexec embedded execution, disguised scheduled tasks, C2 connections, and delivery domains.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | High | The article details process creation, file modification, and network connection events that are well-covered by EDR solutions like Microsoft Defender for Endpoint. |
| Network Visibility | Medium | Network connections to C2 IPs and domains are observable, but the use of TLS to legitimate cloud services (Alibaba Cloud OSS) may blend in with normal traffic. |
| Detection Difficulty | Moderate | While file names and hashes rotate, the behavior patterns (randomized paths, scheduled task creation, defense evasion commands) are consistent and detectable with behavioral analytics. |
Required Log Sources
- DeviceProcessEvents
- DeviceFileEvents
- DeviceNetworkEvents
- Windows Event Logs
- DNS logs
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Executables are being dropped into randomized directories under C:\Users\Public, C:\ProgramData, or C:\Program Files (x86) and launched by unusual parent processes like archiving tools or msiexec.exe. | DeviceProcessEvents, DeviceFileEvents | Execution | Low |
| Scheduled tasks with names imitating routine IT or productivity jobs are launching executables from user-writable directories with a ~60-second re-execution cadence. | DeviceProcessEvents, Scheduled Task logs | Persistence | Low |
| Short-lived scheduled tasks running as SYSTEM are being created to modify Microsoft Defender exclusions and then immediately deleted. | DeviceProcessEvents, Windows Security Event Log (Event ID 4698) | Privilege Escalation, Defense Evasion | Low |
| Processes are executing commands to delete volume shadow copies, disable Windows Update services, or rename system DLLs. | DeviceProcessEvents | Defense Evasion | Low |
| Processes are beaconing to C2 endpoints on non-standard ports or connecting to cloud object storage services for payload delivery. | DeviceNetworkEvents | Command and Control | Medium |
Control Gaps
- Signature-based antivirus may miss dynamically generated payloads with rotating hashes.
- Netblock- and geography-based blocking may miss infrastructure relationships that are only visible at the ASN level.
- Blocking individual C2 domains may be insufficient if the campaign quickly rotates to new domains.
Key Behavioral Indicators
- Process execution from randomized paths under C:\Users\Public<random><random>.exe
- Scheduled tasks with disguised names launching payloads from C:\ProgramData\
- SYSTEM scheduled tasks writing to HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
- Execution of vssadmin delete shadows /all /quiet
- Disabling or renaming Windows Update service components (wuauserv, UsoSvc, WaaSMedicSvc, uhssvc)
- msiexec.exe launching executables from C:\Users\Public\
- svchost.exe executing from non-system paths
- Payloads masquerading as legitimate software (e.g., Philips Speech Driver) with incomplete version metadata (TODO: <Product name>)
False Positive Assessment
Low
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Block the identified C2 IP addresses and domains at the network perimeter.
- Hunt for the identified SHA256 hashes and randomized payload drop patterns in your environment.
- Review scheduled tasks for entries with disguised names launching executables from C:\ProgramData.
- Check Microsoft Defender exclusion lists for unauthorized entries.
Infrastructure Hardening
- Enforce Tamper Protection to block exclusion and registry writes to Microsoft Defender even when the payload runs as SYSTEM.
- Enable Attack Surface Reduction rules, such as blocking executable files from running unless they meet prevalence, age, or trusted list criteria.
- Block ZIP archives named app_setup., zinst., zintall., intsoft., and innstll.* served from *.com.cn or *.hl.cn domains.
- Block the identified delivery endpoints (/712down, /73inst, /7qinst, /ins711) in web and mail flow.
User Protection
- Ensure SmartScreen and Network Protection are enabled to help identify and block malicious downloads.
- Educate users on the risks of downloading software from untrusted sources and to verify the authenticity of download pages.
Security Awareness
- Incorporate awareness of counterfeit software download sites into existing security training programs.
- Advise users to only download software from official vendor websites or trusted app stores.
MITRE ATT&CK Mapping
Resource Development
Execution
Privilege Escalation
Stealth
Defense Impairment
Lateral Movement
Command and Control
Impact
Additional IOCs
- Ips:
47[.]239[.]232[.]245- C2 endpoint observed communicating over port 8050.103[.]183[.]3[.]162- C2 endpoint associated with domain oijfwe.net on port 5090.103[.]156[.]25[.]35- C2 endpoint observed on port 7031.47[.]243[.]218[.]255- C2 endpoint observed communicating over port 28300.161[.]248[.]87[.]157- C2 IP endpoint.43[.]99[.]100[.]248- C2 IP endpoint.47[.]239[.]175[.]163- C2 IP endpoint.47[.]86[.]205[.]97- C2 IP endpoint.
- Domains:
app-microsoft-edge[.]com[.]cn- Spoofed Microsoft Edge download site used as a lure.kaspersky-lab[.]hl[.]cn- Spoofed Kaspersky download site used as a lure.sejda[.]hl[.]cn- Spoofed Sejda PDF download site used as a lure.translate-youdao[.]hl[.]cn- Spoofed NetEase Youdao Dictionary download site used as a lure.zh-diskgenius[.]com[.]cn- Spoofed DiskGenius download site used as a lure.baidu-pan[.]com[.]cn- Spoofed Baidu Netdisk download site used as a lure.ocam-pc[.]com[.]cn- Spoofed oCam Screen Recorder download site used as a lure.cn-drawio[.]com[.]cn- Spoofed draw.io download site used as a lure.steelseries-cn[.]com[.]cn- Spoofed SteelSeries download site used as a lure.gw-sogou[.]com[.]cn- Spoofed Sogou download site used as a lure.calibre-ebook[.]com[.]cn- Spoofed Calibre download site used as a lure.mindmoster[.]com[.]cn- Typosquat domain impersonating MindMaster used as a lure.yimxg25tiy[.]com- Delivery host serving malicious installer archives.cc8ttkv35b[.]com- Delivery host serving malicious installer archives.n7b8t85zsg[.]com- Delivery host serving malicious installer archives.bxfh[.]tzcdq[.]cn- Delivery host serving malicious installer archives.tmsq[.]tzcdq[.]cn- Delivery host serving malicious installer archives.mebx78e02[.]com- Delivery host serving malicious installer archives.qwjre1487[.]com- Delivery host serving malicious installer archives.euioxu[.]net- Six-character .net domain used for command and control.czijbh[.]net- Six-character .net domain used for command and control.wfmwsj[.]net- Six-character .net domain used for command and control.tbdqxq[.]net- Six-character .net domain used for command and control.
- Urls:
hxxp://www[.]gehie246[.]com/712down- Delivery URL serving dynamically generated malicious ZIP archives.hxxps://upitem[.]oss-cn-hangzhou[.]aliyuncs[.]com- Attacker-controlled Alibaba Cloud OSS bucket URL used for C2 over TLS.
- File Hashes:
c4100ad39d8db98f063feb6c3b6c8e9a9f9d9bf25a1e0233f43b058ff8a7dbdf(SHA256) - SHA256 hash of the networking payload.1bd3662d784840e410d2d3c0a1040277f7f549089447359f01e05c2559cb1f17(SHA256) - SHA256 hash of the persistent payload that performs process injection.f33d160d757e4b39019fdef21cf90cafb501b800ca0d4039366bc30856e3d81b(SHA256) - SHA256 hash of the persistent/networking payload.e4fe2dee8f0bb132fa15fc686d1f93df39530a2d3a8d3a1f3a605a057c04e7b3(SHA256) - SHA256 hash of a supporting DLL used in the campaign.
- Registry Keys:
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths- Registry key modified by the malware to add Defender exclusions.HKLM\Software\Policies\Microsoft\Windows\WindowsUpdate\AU- Registry key modified to set NoAutoUpdate and neutralize Windows Update.
- File Paths:
C:\Users\Public\<random>\<random>.exe- World-writable location used for dropping randomized stage-one payloads.C:\Program Files (x86)\<random>\<random>.exe- System location used for staging later-stage payloads.C:\ProgramData\<random>\<random>.exe- System location used for persistent payloads launched by scheduled tasks.C:\Program Files (x86)\72q1o6\XPSPLOG.dll- Malicious DLL loaded by the later-stage payload for DLL side-loading.
- Command Lines:
- Purpose: Privilege escalation to add Microsoft Defender exclusion | Tools:
schtasks.exe,cmd.exe,reg.exe| Stage: Privilege Escalation - Purpose: Add sweeping Microsoft Defender path exclusions | Tools:
powershell.exe| Stage: Defense Evasion |powershell.exe Add-MpPreference -ExclusionPath <paths> -Force - Purpose: Delete volume shadow copies to inhibit recovery | Tools:
cmd.exe,vssadmin.exe| Stage: Defense Evasion |cmd.exe /c vssadmin delete shadows /all /quiet - Purpose: Harden payload directories against removal | Tools:
icacls.exe| Stage: Defense Evasion |icacls "<filepath>" /grant:r Administrators:(OI)(CI)F /grant:r SYSTEM:(OI)(CI)F - Purpose: Stop and disable Windows Update services | Tools:
net.exe,sc.exe| Stage: Defense Evasion - Purpose: Rename Windows Update DLLs | Tools:
takeown.exe,icacls.exe,rename| Stage: Defense Evasion - Purpose: Disable Windows Update scheduled tasks | Tools:
powershell.exe| Stage: Defense Evasion - Purpose: Launch randomized payload via Windows Installer embedded mode | Tools:
msiexec.exe| Stage: Execution |msiexec.exe -Embedding E Global\MSI0000
- Purpose: Privilege escalation to add Microsoft Defender exclusion | Tools: