Posts

Showing posts with the label doc

maldoc dropping Remcos RAT

Image
Files: File name: PLURILITERAL.exe MD5: 6687f5ca89833f38157110f58bba8785 SHA256: 2fdb33e0895ec644222e153ab7ce485c76c8afa07c039b2c4e54aecba1e33c28 Filesize: 274432 bytes File name: PLURILITERAL.vbs MD5: 0495f6d9da19698aa3e4f55ac7f48278 SHA256: efd1a1a236041eea5b7db330b7ca304bb48b052bf2dbefb59395287a64dc1196 Filesize: 108 bytes File name: qwerty2.exe MD5: a85b0bf02ef1504f8cdf2e113294c888 SHA256: c263a793764bedabdf4aebbcc662627f7372e70ad573d42bdb752003b6a70976 Filesize: 274432 bytes File name: Resume.doc (named removed, password:1234) MD5: 8d95ababf5c6566fe65095abf8acff81 SHA256: d4c144873b11177071a5e99f70970afc36bc7a3163b6feee2945d8d37edcb8a9 Filesize: 37888 bytes Download (password: malware) URLs: hxxp://209.141.34[.]8/test1.exe hxxp://toptoptop1[.]online:2404 hxxp://toptoptop2[.]online:2404 hxxp://toptoptop3[.]site:2404 IPs: 103.1.184.108 209.141.34.8 192.64.119.33 Details: Sample source is a password protected malicious ....

.doc dropping NanoCore

Image
Files: File name: BoA_ach_e.remit_notice_0313.doc SHA256 ba01bcf05c68bf2ea9468550cf8405debbe6ef17757c11e0c162544941e39ddf File size 594.0 KB ( 608256 bytes ) File name: jofb.exe SHA256 4275e436de46df0103a63939e24f533f24c46f66c916b38700e49dbe463a9114 File size 423.5 KB ( 433664 bytes ) Download  (password: malware) URLs: hxxp://www.elec-tb[.]com/tmp/jofb.exe hxxp://cassb.ddns[.]net:5050 IPs: 185.112.35.3 178.239.21.201 Details: This sample came attached to an email as a Bank of America themed macro'd .doc file "BoA_ach_e.remit_notice_0313.doc":   Upon enabling content, the macro immediately calls out to a payload site (my setup is not internet connected): I downloaded the payload manually and took a look at the payload site: It is an Iranian electrical product site that appears to have been around for awhile. Appears to be a compromised victim site. I executed the payload while observing ProcessHacker. Process behavior...