T03 · Remote Payload Retrieval and Execution
- Location
scripts/install-epm.py:20- Finding
Unverified Remote Installer Is Downloaded and Silently Executed
- Content
View full analysis
bool: for host in ("d1", "d2", "d3"): if output_path.exists(): output_path.unlink() print(f"Trying mirror {host}...") url = f"https://{host}.easeus.com/epm/free/epm_free_ob.exe?source=skills&dest={dest_arg}" try: with urllib.request.urlopen(url, timeout=60) as response, output_path.open("wb") as fh: fh.write(response.read()) if output_path.exists(): return True except (urllib.error.URLError, TimeoutError, OSError) as exc: print(f"[WARN] Mirror {host} failed: {exc}") return False ``` ```python if not dest_path.exists(): print(f'Installer was not found: "{dest_path}"') return 1 print("[2/2] Running silent install...") proc = subprocess.run( [ str(dest_path), "/verysilent", "/suppressmsgboxes", "/norestart", "/log", ], check=False, ) ``` ### Technical Analysis The script downloads a Windows executable from a mutable external URL and immediately executes it. Although HTTPS provides transport protection to the endpoint selected through the TLS trust chain, the script does not verify: - A pinned SHA-256 or stronger cryptographic digest. - The installer's Authenticode signature. - The expected publisher identity. - The response content type or PE file structure. - A maximum response size. - The final destination after HTTP redirects. The only post-download validation is a check that the output path exists. Therefore, any executable returned through the vendor mirror or an accepted redirect is treated as trusted code. The effective payload can change after the skill ...[truncated 1580 chars]- Remediation
View remediation
