Posts

Showing posts with the label nanocore

BACKLOG: NanoCore and AgentTesla double tap (maybe triple?)

Image
Files: File name: LFPEHS.exe MD5: 450c0d7521b121a919e62401d50a2182 SHA256: 1d9526fe126321b49469341dbac0c9bbb247f896f4f836d93b4f361183e93a5e Filesize: 207872 bytes File name: MMCRLC.vbs MD5: 266f15a950f233e279095158cb2cfe8f SHA256: d391a3570354b37aafe3340aa92da365d533b4edd1adb80fffab14d0cee29a67 Filesize: 858 bytes File name: S007591119000628_XLSX.exe MD5: 792f42f7a4ba4d37015d658e1573cff2 SHA256: c4acc931c61a4b4da44510e645913f78588e2b655bf45790219407cb0b1c3132 Filesize: 1852424 bytes File name: S007591119000628_XLSX.ISO MD5: 2482a65df50ca7ef9d7445dcd5985ada SHA256: bc603a3b6ebf6e1312ad79e8e409c93ac53bfdedb65d961db6bf57cf947a19dd Filesize: 2424832 bytes File name: XAAHKP.exe MD5: 39ee891b8bdbd9ba987b5c4faafb84bd SHA256: 286803e00ea5f401dc94c9b25130716598210f33e4bf4465fb9fa0490231b176 Filesize: 207360 bytes Download  (password: malware) Quick note: These files all originated from the exe inside S007591119000628_XLSX.ISO. No internet connection needed....

.doc dropping NanoCore

Image
Files: File name: BoA_ach_e.remit_notice_0313.doc SHA256 ba01bcf05c68bf2ea9468550cf8405debbe6ef17757c11e0c162544941e39ddf File size 594.0 KB ( 608256 bytes ) File name: jofb.exe SHA256 4275e436de46df0103a63939e24f533f24c46f66c916b38700e49dbe463a9114 File size 423.5 KB ( 433664 bytes ) Download  (password: malware) URLs: hxxp://www.elec-tb[.]com/tmp/jofb.exe hxxp://cassb.ddns[.]net:5050 IPs: 185.112.35.3 178.239.21.201 Details: This sample came attached to an email as a Bank of America themed macro'd .doc file "BoA_ach_e.remit_notice_0313.doc":   Upon enabling content, the macro immediately calls out to a payload site (my setup is not internet connected): I downloaded the payload manually and took a look at the payload site: It is an Iranian electrical product site that appears to have been around for awhile. Appears to be a compromised victim site. I executed the payload while observing ProcessHacker. Process behavior...