ATT&CK · T1218.003 · sub-technique
CMSTP
Tactics: stealth
About
Adversaries may abuse CMSTP to proxy execution of malicious code. The Microsoft Connection Manager Profile Installer (CMSTP.exe) is a command-line program used to install Connection Manager service profiles. CMSTP.exe accepts an installation information file (INF) as a parameter and installs a service profile leveraged for remote access connections. Adversaries may supply CMSTP.exe with INF files infected with malicious commands. Similar to Regsvr32 / ”Squiblydoo”, CMSTP.exe may be abused to load and execute DLLs and/or COM scriptlets (SCT) from remote servers. This execution may also bypass AppLocker and other application control defenses since CMSTP.exe is a legitimate binary that may be signed by Microsoft. CMSTP.exe can also be abused to Bypass User Account Control and execute arbitrary commands from a malicious INF through an auto-elevated COM interface.
Used by actors
2 known groups
Software
2 malware/tools implement this
Corpus indicators tagged with this technique
13 indicators in the corpus carry T1218.003.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| a4fbd707f4ce7ca68e6137cef1c56b6f408e5f0a0f148434d996bb98c3a21fff | sha256 | — | 80 | 2 |
| a73cb9d5d46e19f3daa4a14cfe5d8fa4319a3d62452039e4972e6a316bbb26f4 | sha256 | — | 80 | 2 |
| 20476f3a51dfddf3dc0603fc7858d894 | md5 | phishing | 76 | 1 |
| 2a34bdd25b404737ee5d3b52bf0b3b70 | md5 | phishing | 76 | 1 |
| 3757dccb2adae65ccdf8d5e5c948b927 | md5 | phishing | 76 | 1 |
| 7842d12d9e37c75076133be5b9904cb2 | md5 | phishing | 76 | 1 |
| cc34d9760394104ad47877a0d57e9c63 | md5 | phishing | 76 | 1 |
| 07d7d21c2c0920d198efb9ea54900a80 | md5 | phishing | 76 | 1 |
| http://catalogo.castrouria.com/c84da/bl.txt | url | — | 75 | 1 |
| 64.89.160.17 | ip | — | 70 | 2 |
| 178.16.52.80 | ip | — | 70 | 2 |
| 181.235.8.24 | ip | — | 70 | 2 |
| rema200426.duckdns.org | domain | — | 65 | 2 |