Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

IPsec Helper

IPsec Helper is a post-exploitation remote access tool linked to Agrius operations. This malware shares significant programming and functional overlaps with Apostle ransomware, also linked to Agrius. IPsec Helper provides basic remote access tool functionality such as uploading files from victim systems, running commands, and deploying additional payloads.(Citation: SentinelOne Agrius 2021)
ID: S1132
Type: MALWARE
Platforms: Windows
Created: 22 May 2024
Last Modified: 29 Aug 2024

Techniques Used

Domain ID Name Use
Enterprise T1071 .001 Application Layer Protocol: Web Protocols

IPsec Helper connects to command and control servers via HTTP POST requests based on parameters hard-coded into the malware.(Citation: SentinelOne Agrius 2021)

Enterprise T1059 .001 Command and Scripting Interpreter: PowerShell

IPsec Helper can run arbitrary PowerShell commands passed to it.(Citation: SentinelOne Agrius 2021)

.003 Command and Scripting Interpreter: Windows Command Shell

IPsec Helper can run arbitrary commands passed to it through cmd.exe.(Citation: SentinelOne Agrius 2021)

.005 Command and Scripting Interpreter: Visual Basic

IPsec Helper can run arbitrary Visual Basic scripts and commands passed to it.(Citation: SentinelOne Agrius 2021)

Enterprise T1070 .004 Indicator Removal: File Deletion

IPsec Helper can delete itself when given the appropriate command.(Citation: SentinelOne Agrius 2021)

.009 Indicator Removal: Clear Persistence

IPsec Helper can delete various service traces related to persistent execution when commanded.(Citation: SentinelOne Agrius 2021)

Enterprise T1027 .013 Obfuscated Files or Information: Encrypted/Encoded File

IPsec Helper contains an embedded XML configuration file with an encrypted list of command and control servers. These are written to an external configuration file during execution.(Citation: SentinelOne Agrius 2021)

Enterprise T1569 .002 System Services: Service Execution

IPsec Helper is run as a Windows service in victim environments.(Citation: SentinelOne Agrius 2021)

Enterprise T1497 .003 Virtualization/Sandbox Evasion: Time Based Evasion

IPsec Helper will sleep for a random number of seconds, iterating 200 times over sleeps between one to three seconds, before continuing execution flow.(Citation: SentinelOne Agrius 2021)

Groups That Use This Software

ID Name References
G1030 Agrius

(Citation: SentinelOne Agrius 2021)

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.