[ << ALL_FEED ]

Work order for malware operation

More in General

Work order for malware operation ✍️

In mid-January, the cyber intelligence group recorded a campaign by the hacker group XDSpy targeting organizations in Russia and Belarus. A malicious DLL library and a legitimate executable file are distributed in archives (screenshot 1). PDF documents with contract-themed content are used as lures.

1️⃣ After launching the executable file, a decoy document is displayed to the user (screenshot 2), while the main actions are performed in the background. The contents of the archive are moved to the C:\Users\Public directory, after which the malicious DLL library is injected via the DLL Side-Loading technique.

Persistence in the system is established via an autorun entry HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run with a name matching the name of the legitimate EXE and the value C:\Users\Public{legit_exe_filename}, which ensures automatic launch of the component when the user logs into the system.

2️⃣ At the next stage, network interaction with the attackers’ infrastructure is established. A payload is downloaded from a specified link and saved to C:\Users\Public\ followed by execution.

3️⃣ The group’s domains, from which the next stage is downloaded, deserve special attention.

The body of the HTML page of the attacker-controlled websites contains obfuscated JavaScript (screenshot 3) that performs a preliminary check of telemetry and signs of an automated environment, including the presence of navigator.webdriver, headless indicators in userAgent and appVersion, the validity of the navigator.plugins and navigator.mimeTypes objects, whether language/languages are populated, as well as anomalous outerWidth/outerHeight values. If the client fails the check, instead of serving the subsequent malicious stage, the domain returns a redirect to download a large file for speed testing from the proof.ovh.net domain.

This approach complicates extraction of the next stage and reduces the likelihood that malware researchers will be able to obtain the group’s stage for subsequent reverse engineering. We have previously described a similar XDSpy chain and mechanisms for delivering the next stage.

IoCs

Domains:
weltimkrieg.net
cflbombardier.org
lelacdespassions.org

Archives:
7ce9d21fdd56d0881771502544ce5699
67a8f63c021839e30ee2e1910dc07ff7
3578a1b96820789059393ee9717d431c
919c5f6ce38586bd827a82e97dd44fb1

Malicious DLLs:
e338abdf9c3160be43b0fa2ee9692292
e758df62f6a0e52f37edd91d3fdf84ac
33a72ef5916bafff2c83d0f4e0f2aa16
0cf610531681f5aeef534f333026c6c2

EXE:
96b307d7d8f4c8b9d7aca9f0ee2ede75

Decoy documents:
acd3ca48b3ce0677ecb7ab1ab57936f8
ccc49c64b44977563a1fb7c6af52ceed
df98e0bd1e8e6c20ab07bfe790a6ef6eCode language: YAML (yaml)


#TI #APT #ioc
@ptescalator

More from ti_author

More from ti_author

More in General