• Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Transform
      • SOC Consultancy
      •     SOC Maturity Assessment
      •     SOC Model Evaluation
      •     SOC Gap Analysis
      •     SIEM Gap Analysis
      •     SIEM Optimization
      •     SOC Content Pack
    • Train
      • Security Awareness and Training
      • Tabletop Exercise
      • Simulated Cyber Attack Exercises
    • Respond
      • Incident Response
      • Incident Analysis
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
Rewterz Threat Alert: Fresher Phishing Campaigns Targeting Pakistani Bank Employees
January 29, 2019
Rewterz Threat Alert – Phishing Awareness For Employees and Customers of the Banking Industry
January 30, 2019

Rewterz Threat Alert – GrandCrab and Ursnif Campaign Observed in the Wild

January 29, 2019

SEVERITY: Medium

 

 

CATEGORY: Phishing

 

 

ANALYSIS SUMMARY 

 

 

A campaign distributing both Ursnif malware and GrandCrab ransomware via malicious Word documents attached to phishing emails. The Word documents contained a VBS macro that executes a base64 encoded PowerShell script. The PowerShell script is used to retrieve the files associated with the GrandCrab and Ursnif infections. The first payload that is downloaded and executed is a PowerShell command used to download an additional PowerShell script. This additional PowerShell script contains a base64 encoded PE file which it injects into memory for execution. This PE file was identified to be a variant of the GrandCrab ransomware. The second payload that is download and executed via the VBS macro is the Ursnif executable, which is used for malicious activities such as gathering system information and harvesting credentials.

 

 

 

 

Impact

 

Leakage of system information
Loss of credentials

 

 

INDICATORS OF COMPROMISE

 

 

URLs

 

bevendbrec[.]com
iscondisth[.]com

 

 

Malware Hash (MD5/SHA1/SH256)

 

c064f6f047a4e39014a29c8c95526c3fe90d7bcea5ef0b8f21ea306c27713d1f
d6c53d9341dda1252ada3861898840be4d669abae2b983ab9bf5259b84de7525
0a3f915dd071e862046949885043b3ba61100b946cbc0d84ef7c44d77a50f080

 

 

Remediation

 

Block all URL’s and IoC’s at your respective controls.
Ensure anti virus software and associated files are up to date.
Always be suspicious about emails sent to users from unknown senders.

  • Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Respond
      • Incident Response
      • Incident Analysis
  • Transform
    • SOC Consultancy
    •     SOC Maturity Assessment
    •     SOC Model Evaluation
    •     SOC Gap Analysis
    •     SIEM Gap Analysis
    •     SIEM Optimization
    •     SOC Content Pack
  • Train
    • Security Awareness and Training
    • Tabletop Exercise
    • Simulated Cyber Attack Exercises
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
COPYRIGHT © REWTERZ. ALL RIGHTS RESERVED.