Rewterz Threat Alert – HiddenWasp Malware Affecting Linux
June 3, 2019Rewterz Threat Alert – Outlook Web Mail Phishing Email Asks Targets to Manage Undelivered Email
June 3, 2019Rewterz Threat Alert – HiddenWasp Malware Affecting Linux
June 3, 2019Rewterz Threat Alert – Outlook Web Mail Phishing Email Asks Targets to Manage Undelivered Email
June 3, 2019Severity
Medium
Analysis Summary
A spear phishing campaign distributing a Trojan via an .XLS attachment. It was observed targeting an Italian organization and has been attributed to the threat group TA505. The connection was drawn due to the the use of a command and control server in Germany, previously used by the group in past campaigns. The email attachment itself contains an embedded malicious macro. The infection process begins once the .XLS attachment is opened, ultimately leading to the malware being installed on the victim’s system. It is important to note that in order for the Trojan to be successfully installed, the victim must enable macros. It was reported that the macro source code is extremely obfuscated and contains over sixteen-hundred lines of code.
Indicators of Compromise
IP(s) / Hostname(s)
- 217[.]12[.]201[.]159
- 47[.]245[.]58[.]124
URLs
- kentona[.]su
- https[:]//kentona[.]su/xpepriubgpokejifuv7efrhguskdgfjn/ananas[.]exe
- https[:]//kentona[.]su/xpepriubgpokejifuv7efrhguskdgfjn/pasmmm[.]exe
Malware Hash (MD5/SHA1/SH256)
- 0c88e285b6fc183c96b6f03ca5700cc9ca7c83dfccc6ad14a946d1868d1cc273
- 1ee1ba514212f11a69d002005dfc623b1871cc808f18ddfa2191102bbb9f623b
- fd701894e7ec8d8319bc9b32bba5892b11bdf608c3d04c2f18eff83419eb6df0
- c69ce39ac3e178a89076136af7418c6cb664844b0ce5cb643912ed56c373a08a
- 5310c2397ba4c783f7ee9724711a6da9b5c603b5c9781fff3407b46725e338b3
- aafa83d5e0619e69e64fcac4626cfb298baac54c7251f479721df1c2eb16bee7
- 2b5eefc4bc2d34cbe5093332c47b5405cf5c32e8156767fc8bc9ddd9cdcf3018
- 609b0a416f9b16a6df9b967dc32cd739402af31566e019a8fb8abdf3cb573e30
- 6f1a8ee627ec2ed7e1d818d32a34a163416938eb13a97783a71f9b79843a80a2
Remediation
- Block all threat indicators at your respective controls
- Always be suspicious about emails sent by unknown senders
- Never click on the link/ attachments sent by unknown senders