Rewterz Threat Alert – PKPLUG: Chinese Cyber Espionage Group Attacking Asia
November 7, 2019Rewterz Threat Alert – Trickbot Launches Personalized Spear Phishing Attacks
November 8, 2019Rewterz Threat Alert – PKPLUG: Chinese Cyber Espionage Group Attacking Asia
November 7, 2019Rewterz Threat Alert – Trickbot Launches Personalized Spear Phishing Attacks
November 8, 2019Severity
Medium
Analysis Summary’
Subpoena themed malspam campaigns are found delivering the Predator the thief malware. The phishing email states that the recipient has been subpoenaed and is asked to click on a link to see more details about the case. The enclosed link uses trusted sources—namely Google Docs and Microsoft OneDrive—for the infection chain. The initial Google Docs link is benign and contains a redirect chain that eventually leads to a malicious macro-laden Microsoft Word file. The macro, upon execution, downloads the malware via PowerShell, which is a sample of the Predator the Thief information stealer. The email body, shown in figure below, contains a warning that the recipient has 14 days to comply with the subpoena notice, a scare tactic designed to panic users into clicking. The Google Docs page is themed to fool a user into thinking the service is conducting security checks.
The malware then infects the endpoint and attempts to exfiltrate sensitive data. Below is the infection chain.
Predator the Thief targets cryptocurrency wallets, browser information, FTP, and email credentials. It can also take a screenshot of the infected machine. The information is stored in a file named “information.log” and sent to the Command and Control (C2) server via an HTTP POST to a network endpoint “gate.get” by default. The data in this file contains machine and user fingerprint data, stolen credentials, and network configurations.
Impact
- Information Theft
- Credential Theft
- Crypto-currency Theft
Indicators of Compromise
Domain Name
comrade696[.]xyz
Source IP
- 31[.]184[.]196[.]176
- 193[.]0[.]178[.]46
URL
- hxxp://comrade696[.]xyz/api/gate[.]get
- hxxp://bit[.]do/fcMEx
- hxxp://193[.]0[.]178[.]46/m2Dj5W
- hxxp://comrade696[.]xyz/api/check[.]get
- hxxp://31[.]184[.]196[.]176/file8[.]exe
- hxxps://de5qqw[.]sn[.]files[.]1drv[.]com/details[.]doc
- hxxp://docs[.]google[.]com/document/d/e/2PACX-1vR2ShicgBwEhJsMeJFho3xmeGvs4h3lpp33DGuVYXa0J7nDHSayHNnUqAuy8RgE1V6DN3rgEamM_l6/pub
- hxxp://docs[.]google[.]com/document/d/e/2PACX-1vTJwmMgl4cycKB1H3DLqE6hO7hBtIZV_R8vetvNk2hoHNvQrOQu6guqESe4ongHOe2qeuZl_hcwtpFi/pub
- hxxp://docs[.]google[.]com/document/d/e/2PACX-1vSC7TE8Jw2rj5mFmdo7SNhhVhYI5_chETx0Um8phyExpH2ok1_BYqbFBCmvu5SNE8USRHFQxAAdSUbe/pub
- hxxp://docs[.]google[.]com/document/d/e/2PACX-1vRHdNziiJLKswksr50gCvUFKGZPoB7aJ2X_u09dUvpXauv5zqPi6BRxmNlhpdQ3VoJnyDd-7UWe0eq4/pub
- hxxp://docs[.]google[.]com/document/d/e/2PACX-1vTDBKHYpJMHsTmAPu8Q3q41G3Sfq0398Mwe1bUth_4gbi9Q9X1uvjJ8Qpt1jfiDjkOvlrV3EGbn4pIH/pub
- hxxp://docs[.]google[.]com/document/d/e/2PACX-1vQYPpaggmpXxbXvzYbcuCFnVbVGFiprq8WT3U0cackWI9z6ECOKGQ75Zxi38IIAcR6U2mWRN-I91RJs/pub
- hxxps://www[.]google[.]com/url?q=hxxp://193[.]0[.]178[.]46/m2Dj5W&sa=D&ust=1572032929507000
- hxxp://docs[.]google[.]com/document/d/e/2PACX-1vSpWb2Y8awd5BhJGCiiscMOhddh3Pf53q_E76aMVH4L1Sy50O8V7wXJG8lLILi_woj35v22P2o0GZo/pub
- hxxp://docs[.]google[.]com/document/d/e/2PACX-1vSw-6rt5QaRo630a6nWVkraLUHH1HLP23pfkdYYxe3NS73ITrhzme_r_K0h67RQjrUjYgrVPDDNt9Yn/pub
- hxxp://docs[.]google[.]com/document/d/e/2PACX-1vTMEq8o1xfYAGRQqTnV_YP4IpoYFLRV0x3yagV4J8TC2vPAevx5y6UobCv9Oa9d1W-KzWbintL_fj2w/pub
- hxxp://docs[.]google[.]com/document/d/e/2PACX-1vRJh78bDJcfBuwt_yV7nhNRuboEHUyfET1yhta2BtoyEPBl7OwADQHm9t28gfVQymkltq69smXgYw/pub
- hxxp://docs[.]google[.]com/document/d/e/2PACX-1vRZG0aGBmvWRzXhT-a68tBJcy1PSPA4blZ51daX-OqtXwjGeuEp-0RBbhazOBKi_Z2bE1AO8ejfTP/pub
Remediation
- Block the threat indicators at their respective controls.
- Do not click on links attached in untrusted emails.
- Disable Microsoft macros by default and monitor PowerShell execution.
- Employ endpoint protection solutions that conduct memory analysis to spot the payload execution.