Rewterz Threat Alert – Divergent: Fileless Malware Using NodeJS
September 27, 2019Rewterz Threat Alert – Ongoing Njrat campaign against Middle East
September 30, 2019Rewterz Threat Alert – Divergent: Fileless Malware Using NodeJS
September 27, 2019Rewterz Threat Alert – Ongoing Njrat campaign against Middle East
September 30, 2019Severity
Medium
Analysis Summary
Konni’s APT Group continues to attack malicious documents written in Russian. Konni’s APT Group conducts attacks with Russian-North Korean trade and economic investment documents.
The vector used for the attack is probably the Spear Phishing method, and has been reported in Korea.
The malicious file suspected of being used as an attachment has the name Russia-North Korea-South Korea-Trade and Economic Relations-Investment.doc
The malicious DOC document file contains the following VBA code. If the [Use Content] button is clicked, the VBA malware included inside is activated. And the contents of the document are printed as follows, which makes the user dazzle like a normal document file. VBA code makes connections with malicious C2 servers contained in the ObjectPool zone. The attacker would communicate with the attacker’s server through a combination of instructions contained in the ObjectPool TextBox1 to TextBox3 data and content. The content of object ‘_1629205277’ is hardcoded to communicate with the C2 server ‘panda2019.eu5 [.] Org’ address as follows: And copy ‘certutil.exe’ normal file to ‘mx.exe’ file name, and use it to decode and execute ‘1.txt’ file.
Impact
Exposure of sensitive information
Indicators of Compromise
URLs
http[:]//handicap[.]eu5[.]org/1[.]txt
http[:]//handicap[.]eu5[.]org/4[.]txt
http[:]//handicap[.]eu5[.]org/3[.]txt
http[:]//clean[.]1apps[.]com/1[.]txt
http[:]//clean[.]1apps[.]com/3[.]txt
http[:]//panda2019[.]eu5[.]org/1[.]txt’
http[:]//panda2019[.]eu5[.]org/1[.]txt
Filename
Russia-North Korea-South Korea-Trade and Economic Relations-Investment.doc
Malware Hash (MD5/SHA1/SH256)
- ed63e84985e1af9c4764e6b6ca513ec1c16840fb2534b86f95e31801468be67a
- 4c201f9949804e90f94fe91882cb8aad3e7daf496a7f4e792b9c7fed95ab0726
- 8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd
- 0c81b761f75047ccc4f41371fd8106d4
Remediation
- Block all threat indicators at your respective controls.
- Always be suspicious about emails sent by unknown senders.
- Never click on the link/attachments sent by unknown senders.