CMSTP

T1218.003

Sub-technique of T1218 System Binary Proxy Execution.View on attack.mitre.org

About this technique

Adversaries may abuse CMSTP to proxy execution of malicious code. The Microsoft Connection Manager Profile Installer (CMSTP.exe) is a command-line program used to install Connection Manager service profiles. CMSTP.exe accepts an installation information file (INF) as a parameter and installs a service profile leveraged for remote access connections.

Adversaries may supply CMSTP.exe with INF files infected with malicious commands. Similar to Regsvr32 / ”Squiblydoo”, CMSTP.exe may be abused to load and execute DLLs and/or COM scriptlets (SCT) from remote servers. This execution may also bypass AppLocker and other application control defenses since CMSTP.exe is a legitimate binary that may be signed by Microsoft.

CMSTP.exe can also be abused to Bypass User Account Control and execute arbitrary commands from a malicious INF through an auto-elevated COM interface.

Detection rules11

Rules on DetectionCode tagged with T1218.003.

Sigma7

RuleLevelLog source
Bypass UAC via CMSTPhighwindows / process_creation
CMSTP App Paths Registry Key Modificationhighwindows / registry_event
CMSTP Execution Process Accesshighwindows / process_access
CMSTP Execution Process Creationhighwindows / process_creation
CMSTP UAC Bypass via COM Object Accesshighwindows / process_creation
DLL Loaded From Suspicious Location Via Cmspt.EXEhighwindows / image_load
Outbound Network Connection Initiated By Cmstp.EXEhighwindows / network_connection

Splunk4

RuleTypeRiskData source
CMLUA Or CMSTPLUA UAC BypassTTPNULLSysmon EventID 7
UAC Bypass With Colorui COM ObjectTTPNULLSysmon EventID 7
Wbemprox COM Object ExecutionTTPNULLSysmon EventID 7
Windows Unusual Process Load Mozilla NSS-Mozglue ModuleAnomalyNULLSysmon EventID 7

Groups2

Software2

Campaigns0

None recorded.

Procedure examples4

Groups2

Used byProcedure example
GroupCobalt Group

Cobalt Group has used the command cmstp.exe /s /ns C:\Users\ADMINI~W\AppData\Local\Temp\XKNqbpzl.txt to bypass AppLocker and launch a malicious script.

GroupMuddyWater

MuddyWater has used CMSTP.exe and a malicious INF to execute its POWERSTATS payload.

Software2

Used byProcedure example
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can use CMSTP.exe to install a malicious Microsoft Connection Manager Profile.

MalwareLockBit 3.0

LockBit 3.0 can attempt a CMSTP UAC bypass if it does not have administrative privileges.

References6

  1. Endurant CMSTP July 2018 Open source
    Seetharaman, N. (2018, July 7). Detecting CMSTP-Enabled Code Execution and UAC Bypass With Sysmon.. Retrieved November 17, 2024.
  2. GitHub Ultimate AppLocker Bypass List Open source
    Moe, O. (2018, March 1). Ultimate AppLocker Bypass List. Retrieved April 10, 2018.
  3. MSitPros CMSTP Aug 2017 Open source
    Moe, O. (2017, August 15). Research on CMSTP.exe. Retrieved April 11, 2018.
  4. Microsoft Connection Manager Oct 2009 Open source
    Microsoft. (2009, October 8). How Connection Manager Works. Retrieved April 11, 2018.
  5. Twitter CMSTP Jan 2018 Open source
    Tyrer, N. (2018, January 30). CMSTP.exe - remote .sct execution applocker bypass. Retrieved September 12, 2024.
  6. Twitter CMSTP Usage Jan 2018 Open source
    Carr, N. (2018, January 31). Here is some early bad cmstp.exe... Retrieved September 12, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.