Brazil malspam pushes Astaroth (Guildma) malware

Keypoints

  • A Brazilian malspam campaign uses a Boleto-themed email that impersonates Grupo Solução & CIA to deliver Astaroth (Guildma).
  • The attacker lures victims to a page that pretends to be a DocuSign-like site, which provides a malicious ZIP archive for download.
  • The downloaded ZIP contains a Windows shortcut and a batch file designed to infect a vulnerable Windows host with Astaroth (Guildma).
  • Persistence is achieved via a Windows startup artifact (Startup folder) to keep the infection active on reboot.
  • The infection uses PowerShell and a batch script (and AutoIt components) as part of its execution chain.
  • <liExfiltration is performed via HTTP POST requests to remote hosts as part of data theft.

  • IOCs include specific domains, IPs, file hashes, and filenames associated with the ZIP payload and its components.

MITRE Techniques

  • [T1566.002] Spearphishing Link – ‘Link from email leads to web page pretending to be from Docusign that provides malicious zip archive for download.’
  • [T1105] Ingress Tool Transfer – ‘Downloaded zip archive contains a Windows shortcut and a batch file.’
  • [T1547.001] Boot or Logon Autostart Execution: Startup Folder – ‘Windows shortcut in the infected user’s RoamingMicrosoftWindowsStart MenuProgramsStartup directory to keep the infection persistent.’
  • [T1059.001] PowerShell – ‘C:WindowsSystem32WindowsPowerShellv1.0powershell.exe -windowstyle hidden -Command C:W45784602214Asus.CertificateValidation.2022.1728.641.AutoIt3.exe C:W45784602214Asus.CertificateValidation.2022.1728.641.AutoIt3.log’
  • [T1059.003] Windows Command Shell – ‘Downloaded zip archive contains a Windows shortcut and a batch file.’
  • [T1041] Exfiltration Over C2 Channel – ‘Data exfiltration through HTTP POST requests.’

Indicators of Compromise

  • [URL] hxxp://w7oaer.infocloudgruposolucaoecia[.]link/P05dWVqI0WghlU4/UeWgmk3mU3p8yeyxkUgI8Um1R1/65837/gruposolucaoeciainfocloud
  • [URL] hxxp://www.intangiblesearch[.]it/search/home_page.php?db_name=%3Cscript%20src=%22https://ajax.googleapis.com/ajax/libs/jquery/3.3.1/jquery.min.js%22%3E%3C/script%3E%3Cscript%20type=%22text/javascript%22%20src=%22hxxp://w7oaer.infocloudgruposolucaoecia[.]link/P05dWVqI0WghlU4/UeWgmk3mU3p8yeyxkUgI8Um1R1/65837/gruposolucaoeciainfocloudAvDk.T036%22%3E%3C/script%3E?
  • [URL] hxxp://w7oaer.infocloudgruposolucaoecia[.]link//inc.php?/gruposolucaoeciainfocloud
  • [IP] 172.67.217[.]95:80 – w7oaer.infocloudgruposolucaoecia[.]link
  • [Domain] w7oaer.infocloudgruposolucaoecia[.]link
  • [URL] hxxp://www.intangiblesearch[.]it/search/home_page.php?db_name=… (long)
  • [IP] 172.67.212[.]174:80 – ahaaer.pfktaacgojiozfehwkkimhkbkm[.]cfd
  • [IP] 104.21.11[.]4:80 – cteasc.ijnkwnkxeguxaxmldwyogggwfk[.]sbs
  • [IP] 104.21.25[.]34:80 – hcu11m2mkk2.rouepcgomfhejergdahjcfcugarfcmoa[.]tk
  • [File Hash] f254f9deeb61f0a53e021c6c0859ba4e745169322fe2fb91ad2875f5bf077300
  • [File Name] gruposolucaoeciainfocloud_097.88933.61414.zip
  • [File Hash] 5ca1e9f0e79185dde9655376b8cecc29193ad3e933c7b93dc1a6ce2a60e63bba
  • [File Name] gruposolucaoeciainfocloud_097.88933157.086456.45192.cmd
  • [File Hash] db136e87a5835e56d39c225e00b675727dc73a788f90882ad81a1500ac0a17d6
  • [File Name] gruposolucaoeciainfocloud_097.88933157.086456.45192.lNk
  • [File Path] C:WindowsSystem32WindowsPowerShellv1.0powershell.exe -windowstyle hidden -Command C:W45784602214Asus.CertificateValidation.2022.1728.641.AutoIt3.exe C:W45784602214Asus.CertificateValidation.2022.1728.641.AutoIt3.log
  • [File Path] C:W45784602214Asus.CertificateValidation.2022.1728.641.AutoIt3.exe
  • [File Path] C:W45784602214Asus.CertificateValidation.2022.1728.641.AutoIt3.log
  • [Directory/Artifact] C:UsersPublic – artifact from the infected host

Read more: https://isc.sans.edu/diary/rss/28962