СHavocают

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
Recently, a phishing email fell into our hands. The email subject is in the best traditions of phone spam calls, when someone calls you from the FSB and tries to scam you out of money 🥺
The attackers adopted the scheme: a certain Andreev N. V. intimidates with big words and obliges you to provide the necessary list of documents within a deadline 😳
Clicking on dokumenty.zip redirects the user to the site:
hffp[:]//inforussia[.]org/dokumenty.html
Code language: plaintext (plaintext)• Instead of a zip archive, the link opens an HTML page with HTML smuggling. Inside is a large amount of data encrypted with base64 and add(35). To avoid detection, key method names inside the HTML page are converted into base64 strings. The encrypted payload is saved as Dokument_FSB.exe. • Inside is a dropper. Classically, it dynamically pulls standard functions from KERNEL32.DLL to load shellcode. It uses a custom hashing algorithm:
def calc_hash(function: str, init=0x43AB):
calc_hash = init
for i in function:
calc_hash = (ord(i) + 0x7313 * calc_hash) & 0xffffffff
return calc_hash ^ 0xAB98
Code language: Python (python)But besides this, the following functions are also loaded:
• FindResourceW
• LoadResource
• LockResourceA
• SizeofResource
• RtlIpv6StringToAddressA
• These APIs are used to decrypt the payload itself. In one of the file’s resources are IPv6 addresses separated by 0D 0A characters. These strings are read into a string array, then converted to bytes using RtlIpv6StringToAddressA. After that, the resulting byte array is XORed with a huge string key of 0x2710 bytes. The resulting shellcode is launched in a fiber in style, also dynamically loading the API for this. Inside is the standard demon Havoc loader.
IOCs
2a79d641b2c377474ff640343e77517b21a51315c3736966336372b3da8995b1
7c2f59d9790b816cb6f27a796d7c928046519f7429b7d2bbe53c60a7a55e22a7
ac301b7698ac040f219eb8dfb248595a406b075d91f51116ef60d4dd9f5242ad
inforussia[.]org
193.3.23[.]121
46.29.162[.]93
Code language: plaintext (plaintext)



#TI #Phishing #ioc
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



