Beware of phishing emails disguised as quote requests

Beware of phishing emails disguised as quote requests
AhnLab ASEC reported phishing emails posing as project quote requests that lure recipients into downloading a compressed attachment containing a VBScript and obfuscated PowerShell chain. The attack downloads and executes Remcos RAT through Google Drive, performs UAC bypass and process injection, and uses C2 infrastructure at 102.220.160[.]104:2404. #AhnLabASEC #RemcosRAT #MicrosoftEdgeUpdateExe

Keypoints

  • The phishing emails impersonate project quote requests and encourage victims to open an attached compressed file.
  • The attachment contains a VBScript that helps build an obfuscated PowerShell command by extracting characters from notepad.exe data and applying token substitutions.
  • The PowerShell script decrypts and reconstructs hidden commands, then connects to a C2 server to download additional payload components.
  • The downloaded payload is stored in %APPDATA%Maleic.For and is split into loader, payload, and secondary PowerShell sections.
  • The secondary PowerShell payload creates a ShellWindows COM object to bypass UAC and launches PowerShell through explorer.exe.
  • The loader decrypts the payload with XOR, downloads Remcos RAT, and injects it into MicrosoftEdgeUpdate.exe for execution.
  • Remcos RAT performs remote command execution, keylogging, screen capture, and file manipulation, and sends data to its C2 server.

MITRE Techniques

  • [T1027] Obfuscated Files or Information – The attacker hides the PowerShell content and executable name through token substitution and string reconstruction (‘the executable file name, “powershell,” which is an obfuscation technique’ / ‘replace arbitrary tokens with actual characters and symbols’).
  • [T1059.001] PowerShell – PowerShell is used to run the reconstructed malicious commands and execute payload stages (‘the PowerShell script… executes the reconstructed command’).
  • [T1105] Ingress Tool Transfer – Additional payloads are downloaded from the attacker’s C2 infrastructure and Google Drive (‘connects to the threat actor’s C2 server to download an additional payload’).
  • [T1548.002] Bypass User Account Control – The secondary PowerShell payload uses ShellWindows and explorer.exe to elevate privileges (‘creates a ShellWindows COM object to bypass UAC’).
  • [T1055] Process Injection – The final payload is injected into MicrosoftEdgeUpdate.exe to execute under a legitimate process (‘injects it into the legitimate process MicrosoftEdgeUpdate.Exe’).
  • [T1140] Deobfuscate/Decode Files or Information – The script decodes and decrypts obfuscated strings and payload data (‘decodes the obfuscated string’ / ‘decrypts it using an XOR operation’).
  • [T1071.001] Web Protocols – C2 communication and payload delivery occur via HTTP-based Google Drive download links (‘Hxxp://drive.Google[.]Com/uc?Export=download…’).

Indicators of Compromise

  • [MD5 hash] Sample associated with the phishing and payload chain – af87821d3cb4f1d72bfb8002437593ec
  • [URL] Additional payload download locations hosted on Google Drive – https[:]//drive[.]google[.]com/uc?export=download&id=1ge2-tdX0-_A6ZU6FDMEFynhz1m0L5lHm, https[:]//drive[.]google[.]com/uc?export=download&id=1yJZysgMU6LZmCZtpko0y1uO1jsbYDIRO
  • [IP:Port] Remcos RAT C2 server used for command-and-control – 102.220.160[.]104:2404
  • [File path] Payload storage location in user profile data – %APPDATA%Maleic.For
  • [File name] Legitimate processes abused for execution and injection – notepad.Exe, explorer.Exe, MicrosoftEdgeUpdate.Exe
  • [CLSID] ShellWindows object used for UAC bypass – {9BA05972-F6A8-11CF-A442-00A0C90A8F39}


Read more: https://asec.ahnlab.com/en/95599/