AhnLab ASEC reported phishing emails posing as project quote requests that lure recipients into downloading a compressed attachment containing a VBScript and obfuscated PowerShell chain. The attack downloads and executes Remcos RAT through Google Drive, performs UAC bypass and process injection, and uses C2 infrastructure at 102.220.160[.]104:2404. #AhnLabASEC #RemcosRAT #MicrosoftEdgeUpdateExe
Keypoints
- The phishing emails impersonate project quote requests and encourage victims to open an attached compressed file.
- The attachment contains a VBScript that helps build an obfuscated PowerShell command by extracting characters from notepad.exe data and applying token substitutions.
- The PowerShell script decrypts and reconstructs hidden commands, then connects to a C2 server to download additional payload components.
- The downloaded payload is stored in %APPDATA%Maleic.For and is split into loader, payload, and secondary PowerShell sections.
- The secondary PowerShell payload creates a ShellWindows COM object to bypass UAC and launches PowerShell through explorer.exe.
- The loader decrypts the payload with XOR, downloads Remcos RAT, and injects it into MicrosoftEdgeUpdate.exe for execution.
- Remcos RAT performs remote command execution, keylogging, screen capture, and file manipulation, and sends data to its C2 server.
MITRE Techniques
- [T1027] Obfuscated Files or Information – The attacker hides the PowerShell content and executable name through token substitution and string reconstruction (‘the executable file name, “powershell,” which is an obfuscation technique’ / ‘replace arbitrary tokens with actual characters and symbols’).
- [T1059.001] PowerShell – PowerShell is used to run the reconstructed malicious commands and execute payload stages (‘the PowerShell script… executes the reconstructed command’).
- [T1105] Ingress Tool Transfer – Additional payloads are downloaded from the attacker’s C2 infrastructure and Google Drive (‘connects to the threat actor’s C2 server to download an additional payload’).
- [T1548.002] Bypass User Account Control – The secondary PowerShell payload uses ShellWindows and explorer.exe to elevate privileges (‘creates a ShellWindows COM object to bypass UAC’).
- [T1055] Process Injection – The final payload is injected into MicrosoftEdgeUpdate.exe to execute under a legitimate process (‘injects it into the legitimate process MicrosoftEdgeUpdate.Exe’).
- [T1140] Deobfuscate/Decode Files or Information – The script decodes and decrypts obfuscated strings and payload data (‘decodes the obfuscated string’ / ‘decrypts it using an XOR operation’).
- [T1071.001] Web Protocols – C2 communication and payload delivery occur via HTTP-based Google Drive download links (‘Hxxp://drive.Google[.]Com/uc?Export=download…’).
Indicators of Compromise
- [MD5 hash] Sample associated with the phishing and payload chain – af87821d3cb4f1d72bfb8002437593ec
- [URL] Additional payload download locations hosted on Google Drive – https[:]//drive[.]google[.]com/uc?export=download&id=1ge2-tdX0-_A6ZU6FDMEFynhz1m0L5lHm, https[:]//drive[.]google[.]com/uc?export=download&id=1yJZysgMU6LZmCZtpko0y1uO1jsbYDIRO
- [IP:Port] Remcos RAT C2 server used for command-and-control – 102.220.160[.]104:2404
- [File path] Payload storage location in user profile data – %APPDATA%Maleic.For
- [File name] Legitimate processes abused for execution and injection – notepad.Exe, explorer.Exe, MicrosoftEdgeUpdate.Exe
- [CLSID] ShellWindows object used for UAC bypass – {9BA05972-F6A8-11CF-A442-00A0C90A8F39}
Read more: https://asec.ahnlab.com/en/95599/