Beware of Phishing Emails That Disguise Themselves as Project Material Purchase Requests

Beware of Phishing Emails That Disguise Themselves as Project Material Purchase Requests
ASEC reported phishing emails impersonating employees of a Korean company and luring victims into opening a malicious XLS file that abuses CVE-2017-0199 to fetch an HTA payload, then a steganographic PNG-delivered loader and finally Remcos RAT. The attack uses layered execution via WMI and obfuscated PowerShell to deploy the malware and exfiltrate data through C2 servers, including 172.245.209.133, blessedongrace.duckdns.org, and muddy-sound-e0cd.nodetectonn.workers.dev. #CVE-2017-0199 #RemcosRAT #AhnLabASEC #172245209133 #blessedongraceduckdnsorg #muddy-sound-e0cdnodetectonnworkersdev

Keypoints

  • ASEC identified phishing emails disguised as project material purchase request forms.
  • The emails impersonated employees of a specific company in Korea to increase credibility.
  • Victims were tricked into opening a malicious XLS attachment that displayed a legitimate-looking decoy form.
  • The document exploited CVE-2017-0199 through OLE2Link to download and run a malicious HTA file.
  • The HTA file used WMI Win32_Process.Create() to launch an obfuscated PowerShell script in the background.
  • The PowerShell script downloaded a steganographic PNG, extracted a Base64-encoded .NET loader, and used it to deploy Remcos RAT.
  • Remcos RAT enabled remote command execution, keylogging, screen capture, file manipulation, and C2 communication.

MITRE Techniques

  • [T1566.001] Phishing: Spearphishing Attachment – Used email attachments to deliver the initial lure, with a malicious XLS disguised as a project material purchase request form (‘trick recipients into opening a malicious XLS file attached to the email’).
  • [T1203] Exploitation for Client Execution – The XLS document abused CVE-2017-0199 to trigger execution when opened (‘it automatically accesses an external URL to download and execute additional malicious files’).
  • [T1221] Template Injection – The malicious Office document used a decoy form to lower suspicion while hiding the exploit content (‘contents of a legitimate project material purchase request form are displayed’).
  • [T1105] Ingress Tool Transfer – The malware downloaded additional payloads from remote servers, including HTA, PNG, and the final RAT (‘downloads and executes a malicious HTA file’, ‘downloads a steganographically embedded PNG file’).
  • [T1059.001] PowerShell – The attacker executed an obfuscated PowerShell script to continue the infection chain (‘execute an obfuscated PowerShell script in the background’).
  • [T1047] Windows Management Instrumentation – WMI was used to launch the malicious script via Win32_Process.Create() (‘uses the Win32_Process.Create() method of WMI’).
  • [T1027] Obfuscated Files or Information – The HTA and PowerShell content were obfuscated to hinder analysis (‘Part of the malicious HTA script before obfuscation’, ‘after obfuscation’).
  • [T1027.003] Steganography – A PNG file containing hidden data was used to deliver the loader payload (‘downloads a steganographically embedded PNG file’).
  • [T1140] Deobfuscate/Decode Files or Information – The script extracted and decrypted Base64-encoded loader data from the PNG (‘extracts a Base64-encoded .NET loader-type malware’).
  • [T1106] Native API – The loader used system capabilities to load and execute payload in memory (‘loads it into memory, and executes it’).
  • [T1071.001] Web Protocols – The malware communicated with C2 servers over HTTP/HTTPS to retrieve and send data (‘communication with the C2 server’).
  • [T1056.001] Keylogging – Remcos RAT collected keystrokes from the infected system (‘such as keylogging’).
  • [T1113] Screen Capture – Remcos RAT captured the victim’s screen (‘screen capture’).
  • [T1020] Data Exfiltration – Collected information and execution results were transmitted externally to the C2 server (‘The collected information and execution results are transmitted externally’).

Indicators of Compromise

  • [IP address ] HTA/PNG/loader delivery and related C2 activity – 172.245.209.133, and 2 more URLs
  • [Domain ] final C2 for Remcos RAT – blessedongrace.duckdns.org, muddy-sound-e0cd.nodetectonn.workers.dev
  • [URL path ] malware download locations – /70/Weprovideforbesthingstocomebackgoodthings.Hta, /70/Img_201031.png, and /HIsPq
  • [File type/name ] malicious attachment and embedded payloads – XLS attachment, HTA file, and PNG file with steganography
  • [MD5 hash ] sample files observed in the campaign – 5055c7b0ae1f6f77b16eb744a76cc453, 623bc9114d118592170599585e5cf60e, and 1 more hash


Read more: https://asec.ahnlab.com/en/95598/