ASEC reported phishing emails impersonating employees of a Korean company and luring victims into opening a malicious XLS file that abuses CVE-2017-0199 to fetch an HTA payload, then a steganographic PNG-delivered loader and finally Remcos RAT. The attack uses layered execution via WMI and obfuscated PowerShell to deploy the malware and exfiltrate data through C2 servers, including 172.245.209.133, blessedongrace.duckdns.org, and muddy-sound-e0cd.nodetectonn.workers.dev. #CVE-2017-0199 #RemcosRAT #AhnLabASEC #172245209133 #blessedongraceduckdnsorg #muddy-sound-e0cdnodetectonnworkersdev
Keypoints
- ASEC identified phishing emails disguised as project material purchase request forms.
- The emails impersonated employees of a specific company in Korea to increase credibility.
- Victims were tricked into opening a malicious XLS attachment that displayed a legitimate-looking decoy form.
- The document exploited CVE-2017-0199 through OLE2Link to download and run a malicious HTA file.
- The HTA file used WMI Win32_Process.Create() to launch an obfuscated PowerShell script in the background.
- The PowerShell script downloaded a steganographic PNG, extracted a Base64-encoded .NET loader, and used it to deploy Remcos RAT.
- Remcos RAT enabled remote command execution, keylogging, screen capture, file manipulation, and C2 communication.
MITRE Techniques
- [T1566.001] Phishing: Spearphishing Attachment â Used email attachments to deliver the initial lure, with a malicious XLS disguised as a project material purchase request form (âtrick recipients into opening a malicious XLS file attached to the emailâ).
- [T1203] Exploitation for Client Execution â The XLS document abused CVE-2017-0199 to trigger execution when opened (âit automatically accesses an external URL to download and execute additional malicious filesâ).
- [T1221] Template Injection â The malicious Office document used a decoy form to lower suspicion while hiding the exploit content (âcontents of a legitimate project material purchase request form are displayedâ).
- [T1105] Ingress Tool Transfer â The malware downloaded additional payloads from remote servers, including HTA, PNG, and the final RAT (âdownloads and executes a malicious HTA fileâ, âdownloads a steganographically embedded PNG fileâ).
- [T1059.001] PowerShell â The attacker executed an obfuscated PowerShell script to continue the infection chain (âexecute an obfuscated PowerShell script in the backgroundâ).
- [T1047] Windows Management Instrumentation â WMI was used to launch the malicious script via Win32_Process.Create() (âuses the Win32_Process.Create() method of WMIâ).
- [T1027] Obfuscated Files or Information â The HTA and PowerShell content were obfuscated to hinder analysis (âPart of the malicious HTA script before obfuscationâ, âafter obfuscationâ).
- [T1027.003] Steganography â A PNG file containing hidden data was used to deliver the loader payload (âdownloads a steganographically embedded PNG fileâ).
- [T1140] Deobfuscate/Decode Files or Information â The script extracted and decrypted Base64-encoded loader data from the PNG (âextracts a Base64-encoded .NET loader-type malwareâ).
- [T1106] Native API â The loader used system capabilities to load and execute payload in memory (âloads it into memory, and executes itâ).
- [T1071.001] Web Protocols â The malware communicated with C2 servers over HTTP/HTTPS to retrieve and send data (âcommunication with the C2 serverâ).
- [T1056.001] Keylogging â Remcos RAT collected keystrokes from the infected system (âsuch as keyloggingâ).
- [T1113] Screen Capture â Remcos RAT captured the victimâs screen (âscreen captureâ).
- [T1020] Data Exfiltration â Collected information and execution results were transmitted externally to the C2 server (âThe collected information and execution results are transmitted externallyâ).
Indicators of Compromise
- [IP address ] HTA/PNG/loader delivery and related C2 activity â 172.245.209.133, and 2 more URLs
- [Domain ] final C2 for Remcos RAT â blessedongrace.duckdns.org, muddy-sound-e0cd.nodetectonn.workers.dev
- [URL path ] malware download locations â /70/Weprovideforbesthingstocomebackgoodthings.Hta, /70/Img_201031.png, and /HIsPq
- [File type/name ] malicious attachment and embedded payloads â XLS attachment, HTA file, and PNG file with steganography
- [MD5 hash ] sample files observed in the campaign â 5055c7b0ae1f6f77b16eb744a76cc453, 623bc9114d118592170599585e5cf60e, and 1 more hash
Read more: https://asec.ahnlab.com/en/95598/