An investigation traced a loader chain beginning with a ClickFix lure through a legitimately signed IBM SPSS IDE binary used for DLL sideloading, four decoy DLLs, and EnumTimeFormatsEx callback abuse for shellcode execution. The final payload is CNCMachineRMS, a 1.14 MB x64 remote administration implant with no static imports, stack-built strings, a custom binary container format for config and C2, and a custom scripting language. The implant provides an interactive shell, file manager, screen capture, local account backdoor, seven persistence mechanisms, and twenty commands for staging additional payloads. C2 communication uses DNS over HTTPS to bypass internal DNS monitoring and beacons every 600 seconds to notepadreleased.com or 85.158.110.78 over TCP/443.
EnumTimeFormatsEx
1 post
CNCMachineRMS: The Undocumented RAT At the End of a BabaDeda Chain