Phishing Emails Use Fake Purchase Requests to Deliver Remcos RAT

· Original article ↗

Summary

AhnLab reports phishing emails impersonating employees of a Korean company. A disguised XLS exploits CVE-2017-0199 to run a chain that ultimately installs Remcos RAT, which can collect information and execute remote commands.

Key points

  • The emails impersonate employees and use a project-material purchase request as a lure to get recipients to open an attached XLS file.
  • The XLS exploits the OLE2Link vulnerability CVE-2017-0199 to retrieve and execute a malicious HTA file.
  • The HTA uses WMI to run an obfuscated PowerShell script, which extracts a .NET loader hidden in a PNG using steganography.
  • The loader downloads and executes Remcos RAT.
  • Remcos can execute remote commands, collect system and user information, capture keystrokes and screens, and manipulate files.
  • AhnLab advises verifying sender addresses and URLs and treating unexpected attachments and requests for sensitive information with caution.

Article Details

Attack Vectors
  • Phishing emails impersonate employees of a company in Korea and attach an XLS file disguised as a project material purchase request.
  • Opening the XLS file triggers CVE-2017-0199 through its OLE2Link content, causing Microsoft Office to download and execute a malicious HTA file.
  • The HTA file uses WMI to launch an obfuscated PowerShell script. The script retrieves a steganographic PNG, extracts and decrypts an embedded .NET loader, and executes it in memory. The loader then downloads Remcos RAT.
Defensive Notes
  • Verify that the sender's email address uses the organization's official domain.
  • Inspect links before clicking and check attachments for suspicious file extensions.
  • Verify a website's URL before entering credentials or other sensitive information; do not enter them on a suspicious page.

Indicators of compromise

TypeIndicatorContext
HOSTNAMEblessedongrace[.]duckdns[.]orgRemcos RAT C2 host, listed with port 19700.
MD55055c7b0ae1f6f77b16eb744a76cc453MD5 hash listed among the article's threat indicators; the associated file is not specified.
MD5623bc9114d118592170599585e5cf60eMD5 hash listed among the article's threat indicators; the associated file is not specified.
MD5db9ff235eae552276b12622ae9105f1cMD5 hash listed among the article's threat indicators; the associated file is not specified.
URLhxxp[:]//172[.]245[.]209[.]133/70/Img_201031[.]PngURL identified as the Remcos RAT download C2.
URLhxxp[:]//172[.]245[.]209[.]133/70/img_201031[.]pngURL listed as a Remcos RAT download indicator.
URLhxxp[:]//172[.]245[.]209[.]133/70/Weprovideforbesthingstocomebackgoodthings[.]HtaC2 URL used to download the malicious HTA file.
URLhxxp[:]//172[.]245[.]209[.]133/70/weprovideforbesthingstocomebackgoodthings[.]htaURL listed as a malicious HTA download indicator.
URLhxxp[:]//blessedongrace[.]duckdns[.]org/URL listed for the Remcos RAT C2 host.
URLhxxp[:]//muddy-sound-e0cd[.]nodetectonn[.]workers[.]dev/HIsPqURL used to download the steganographic PNG containing an encoded loader.
URLhxxps[:]//muddy-sound-e0cd[.]nodetectonn[.]workers[.]dev/HIsPqURL listed for the steganographic PNG download.

MITRE ATT&CK

CVE

Malware

Vendors

Products

Countries

Related Articles