#maltax — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #maltax, aggregated by home.social.
-
Today is "#tax day" here in the US, when people who have not requested an extension must file their #taxes to the IRS.
If you use a tax preparer to fill out the paperwork for you, it may interest you (and your accountant) to know that there has been a concerted campaign by unknown threat actors to try to target smaller CPA or accountant firms with #malware. These attacks look like a blend of social engineering and malicious-document delivery, which results in an infection with a data-stealing RAT.
https://news.sophos.com/en-us/2023/04/13/tax-firms-targeted-by-precision-malware-attacks/
Likewise, if you electronically file your own returns, apparently there was a compromise that persisted for weeks at the website efile[.]com where people who were trying to submit their tax returns were infected with a "drive by" Javascript malware
And if you're one of the happy people who filed an extension, you don't have to sweat this for another six months.
Happy #maltax day, everyone.
-
Today is "#tax day" here in the US, when people who have not requested an extension must file their #taxes to the IRS.
If you use a tax preparer to fill out the paperwork for you, it may interest you (and your accountant) to know that there has been a concerted campaign by unknown threat actors to try to target smaller CPA or accountant firms with #malware. These attacks look like a blend of social engineering and malicious-document delivery, which results in an infection with a data-stealing RAT.
https://news.sophos.com/en-us/2023/04/13/tax-firms-targeted-by-precision-malware-attacks/
Likewise, if you electronically file your own returns, apparently there was a compromise that persisted for weeks at the website efile[.]com where people who were trying to submit their tax returns were infected with a "drive by" Javascript malware
And if you're one of the happy people who filed an extension, you don't have to sweat this for another six months.
Happy #maltax day, everyone.
-
Today is "#tax day" here in the US, when people who have not requested an extension must file their #taxes to the IRS.
If you use a tax preparer to fill out the paperwork for you, it may interest you (and your accountant) to know that there has been a concerted campaign by unknown threat actors to try to target smaller CPA or accountant firms with #malware. These attacks look like a blend of social engineering and malicious-document delivery, which results in an infection with a data-stealing RAT.
https://news.sophos.com/en-us/2023/04/13/tax-firms-targeted-by-precision-malware-attacks/
Likewise, if you electronically file your own returns, apparently there was a compromise that persisted for weeks at the website efile[.]com where people who were trying to submit their tax returns were infected with a "drive by" Javascript malware
And if you're one of the happy people who filed an extension, you don't have to sweat this for another six months.
Happy #maltax day, everyone.
-
Today is "#tax day" here in the US, when people who have not requested an extension must file their #taxes to the IRS.
If you use a tax preparer to fill out the paperwork for you, it may interest you (and your accountant) to know that there has been a concerted campaign by unknown threat actors to try to target smaller CPA or accountant firms with #malware. These attacks look like a blend of social engineering and malicious-document delivery, which results in an infection with a data-stealing RAT.
https://news.sophos.com/en-us/2023/04/13/tax-firms-targeted-by-precision-malware-attacks/
Likewise, if you electronically file your own returns, apparently there was a compromise that persisted for weeks at the website efile[.]com where people who were trying to submit their tax returns were infected with a "drive by" Javascript malware
And if you're one of the happy people who filed an extension, you don't have to sweat this for another six months.
Happy #maltax day, everyone.
-
Today is "#tax day" here in the US, when people who have not requested an extension must file their #taxes to the IRS.
If you use a tax preparer to fill out the paperwork for you, it may interest you (and your accountant) to know that there has been a concerted campaign by unknown threat actors to try to target smaller CPA or accountant firms with #malware. These attacks look like a blend of social engineering and malicious-document delivery, which results in an infection with a data-stealing RAT.
https://news.sophos.com/en-us/2023/04/13/tax-firms-targeted-by-precision-malware-attacks/
Likewise, if you electronically file your own returns, apparently there was a compromise that persisted for weeks at the website efile[.]com where people who were trying to submit their tax returns were infected with a "drive by" Javascript malware
And if you're one of the happy people who filed an extension, you don't have to sweat this for another six months.
Happy #maltax day, everyone.
-
@GossiTheDog @da_667 Someone really ought to come up with a practical cloud file sharing solution that will send everything someone puts online through detonation on a private sandbox and makes a determination that the file is safe before permitting others to download it. It's not especially difficult, it's just a complex problem waiting to be solved that nobody wants to tackle. This was one of the things I've been thinking about since finding out about the #GuLoader #maltax story
-
@GossiTheDog @da_667 Someone really ought to come up with a practical cloud file sharing solution that will send everything someone puts online through detonation on a private sandbox and makes a determination that the file is safe before permitting others to download it. It's not especially difficult, it's just a complex problem waiting to be solved that nobody wants to tackle. This was one of the things I've been thinking about since finding out about the #GuLoader #maltax story
-
@GossiTheDog @da_667 Someone really ought to come up with a practical cloud file sharing solution that will send everything someone puts online through detonation on a private sandbox and makes a determination that the file is safe before permitting others to download it. It's not especially difficult, it's just a complex problem waiting to be solved that nobody wants to tackle. This was one of the things I've been thinking about since finding out about the #GuLoader #maltax story
-
@GossiTheDog @da_667 Someone really ought to come up with a practical cloud file sharing solution that will send everything someone puts online through detonation on a private sandbox and makes a determination that the file is safe before permitting others to download it. It's not especially difficult, it's just a complex problem waiting to be solved that nobody wants to tackle. This was one of the things I've been thinking about since finding out about the #GuLoader #maltax story
-
@GossiTheDog @da_667 Someone really ought to come up with a practical cloud file sharing solution that will send everything someone puts online through detonation on a private sandbox and makes a determination that the file is safe before permitting others to download it. It's not especially difficult, it's just a complex problem waiting to be solved that nobody wants to tackle. This was one of the things I've been thinking about since finding out about the #GuLoader #maltax story
-
In the end, #Remcos is a well-understood and (to put it kindly) a "mature" #malware family that we have a lot of behavioral and dynamic detections for.
The customer, in this case, learned a valuable lesson about social engineering - one that (we hope) many tax preparers will be more aware of in the future.
The threats from this attacker appear to be fairly widely targeted at SMB tax preparer and CPA companies. These are precisely the kinds of companies that might be under-protected and oversaturated with desirable financial data that could be stolen and used for identity theft, credit fraud, tax refund theft, or any number of other financial crimes.
For those who like to play around with this stuff, we have a comprehensive list of IOCs pertaining to this research on our Github. https://github.com/sophoslabs/IoCs/blob/master/Troj_GuLoader.csv
And here's a link to our blog post: https://news.sophos.com/en-us/2023/04/13/tax-firms-targeted-by-precision-malware-attacks/
Shoutouts to Red Canary and eSentire who also posted about this #maltax attack vector recently.
/end
-
In the end, #Remcos is a well-understood and (to put it kindly) a "mature" #malware family that we have a lot of behavioral and dynamic detections for.
The customer, in this case, learned a valuable lesson about social engineering - one that (we hope) many tax preparers will be more aware of in the future.
The threats from this attacker appear to be fairly widely targeted at SMB tax preparer and CPA companies. These are precisely the kinds of companies that might be under-protected and oversaturated with desirable financial data that could be stolen and used for identity theft, credit fraud, tax refund theft, or any number of other financial crimes.
For those who like to play around with this stuff, we have a comprehensive list of IOCs pertaining to this research on our Github. https://github.com/sophoslabs/IoCs/blob/master/Troj_GuLoader.csv
And here's a link to our blog post: https://news.sophos.com/en-us/2023/04/13/tax-firms-targeted-by-precision-malware-attacks/
Shoutouts to Red Canary and eSentire who also posted about this #maltax attack vector recently.
/end
-
In the end, #Remcos is a well-understood and (to put it kindly) a "mature" #malware family that we have a lot of behavioral and dynamic detections for.
The customer, in this case, learned a valuable lesson about social engineering - one that (we hope) many tax preparers will be more aware of in the future.
The threats from this attacker appear to be fairly widely targeted at SMB tax preparer and CPA companies. These are precisely the kinds of companies that might be under-protected and oversaturated with desirable financial data that could be stolen and used for identity theft, credit fraud, tax refund theft, or any number of other financial crimes.
For those who like to play around with this stuff, we have a comprehensive list of IOCs pertaining to this research on our Github. https://github.com/sophoslabs/IoCs/blob/master/Troj_GuLoader.csv
And here's a link to our blog post: https://news.sophos.com/en-us/2023/04/13/tax-firms-targeted-by-precision-malware-attacks/
Shoutouts to Red Canary and eSentire who also posted about this #maltax attack vector recently.
/end
-
In the end, #Remcos is a well-understood and (to put it kindly) a "mature" #malware family that we have a lot of behavioral and dynamic detections for.
The customer, in this case, learned a valuable lesson about social engineering - one that (we hope) many tax preparers will be more aware of in the future.
The threats from this attacker appear to be fairly widely targeted at SMB tax preparer and CPA companies. These are precisely the kinds of companies that might be under-protected and oversaturated with desirable financial data that could be stolen and used for identity theft, credit fraud, tax refund theft, or any number of other financial crimes.
For those who like to play around with this stuff, we have a comprehensive list of IOCs pertaining to this research on our Github. https://github.com/sophoslabs/IoCs/blob/master/Troj_GuLoader.csv
And here's a link to our blog post: https://news.sophos.com/en-us/2023/04/13/tax-firms-targeted-by-precision-malware-attacks/
Shoutouts to Red Canary and eSentire who also posted about this #maltax attack vector recently.
/end
-
In the end, #Remcos is a well-understood and (to put it kindly) a "mature" #malware family that we have a lot of behavioral and dynamic detections for.
The customer, in this case, learned a valuable lesson about social engineering - one that (we hope) many tax preparers will be more aware of in the future.
The threats from this attacker appear to be fairly widely targeted at SMB tax preparer and CPA companies. These are precisely the kinds of companies that might be under-protected and oversaturated with desirable financial data that could be stolen and used for identity theft, credit fraud, tax refund theft, or any number of other financial crimes.
For those who like to play around with this stuff, we have a comprehensive list of IOCs pertaining to this research on our Github. https://github.com/sophoslabs/IoCs/blob/master/Troj_GuLoader.csv
And here's a link to our blog post: https://news.sophos.com/en-us/2023/04/13/tax-firms-targeted-by-precision-malware-attacks/
Shoutouts to Red Canary and eSentire who also posted about this #maltax attack vector recently.
/end
-
Here's a tiny slice of what was on the other end of that extremely weird PowerShell command line.
It's a Visual Basic Script (aka #VBScript) that is chock-full of obfuscatory badness. Long, word-salad variable names; Giant blocks of encoded data broken into dozens of smaller chunks, with a script to concatenate them back into a big data blob, convert them, and deploy. This is the main #GuLoader infector.
We go into a lot more detail of how it works in the blog, but the tl;dr is that this script contains the #Remcos #malware payload, part of which it inserts into the Windows Registry in an encoded form. It then sets up a Scheduled Task to invoke a command that retrieves the Registry data, decode it, and then reflectively inject it into legitimate processes, so the malware is never written to the file system of the infected machine.
7/
-
Here's a tiny slice of what was on the other end of that extremely weird PowerShell command line.
It's a Visual Basic Script (aka #VBScript) that is chock-full of obfuscatory badness. Long, word-salad variable names; Giant blocks of encoded data broken into dozens of smaller chunks, with a script to concatenate them back into a big data blob, convert them, and deploy. This is the main #GuLoader infector.
We go into a lot more detail of how it works in the blog, but the tl;dr is that this script contains the #Remcos #malware payload, part of which it inserts into the Windows Registry in an encoded form. It then sets up a Scheduled Task to invoke a command that retrieves the Registry data, decode it, and then reflectively inject it into legitimate processes, so the malware is never written to the file system of the infected machine.
7/
-
Here's a tiny slice of what was on the other end of that extremely weird PowerShell command line.
It's a Visual Basic Script (aka #VBScript) that is chock-full of obfuscatory badness. Long, word-salad variable names; Giant blocks of encoded data broken into dozens of smaller chunks, with a script to concatenate them back into a big data blob, convert them, and deploy. This is the main #GuLoader infector.
We go into a lot more detail of how it works in the blog, but the tl;dr is that this script contains the #Remcos #malware payload, part of which it inserts into the Windows Registry in an encoded form. It then sets up a Scheduled Task to invoke a command that retrieves the Registry data, decode it, and then reflectively inject it into legitimate processes, so the malware is never written to the file system of the infected machine.
7/
-
Here's a tiny slice of what was on the other end of that extremely weird PowerShell command line.
It's a Visual Basic Script (aka #VBScript) that is chock-full of obfuscatory badness. Long, word-salad variable names; Giant blocks of encoded data broken into dozens of smaller chunks, with a script to concatenate them back into a big data blob, convert them, and deploy. This is the main #GuLoader infector.
We go into a lot more detail of how it works in the blog, but the tl;dr is that this script contains the #Remcos #malware payload, part of which it inserts into the Windows Registry in an encoded form. It then sets up a Scheduled Task to invoke a command that retrieves the Registry data, decode it, and then reflectively inject it into legitimate processes, so the malware is never written to the file system of the infected machine.
7/
-
Here's a tiny slice of what was on the other end of that extremely weird PowerShell command line.
It's a Visual Basic Script (aka #VBScript) that is chock-full of obfuscatory badness. Long, word-salad variable names; Giant blocks of encoded data broken into dozens of smaller chunks, with a script to concatenate them back into a big data blob, convert them, and deploy. This is the main #GuLoader infector.
We go into a lot more detail of how it works in the blog, but the tl;dr is that this script contains the #Remcos #malware payload, part of which it inserts into the Windows Registry in an encoded form. It then sets up a Scheduled Task to invoke a command that retrieves the Registry data, decode it, and then reflectively inject it into legitimate processes, so the malware is never written to the file system of the infected machine.
7/
-
What's up with that #GuLoader URL?
The command uses a URL format that looks like a hexadecimal value, a dot, and then a decimal number.
It turns out that this is a variation of the so-called #dotless IP address format.
Back in 1999, there was a vulnerability in Internet Explorer where someone figured out this very odd bug. CVE-1999-1087 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1087 aka MS98-016) describes this bug and the strange formatting of the URL.
Back then, @threatresearch created a little Excel spreadsheet that shows how to do this conversion. In essence, a dotless IP address is the decimal representation of a hexadecimal representation of the four octets in an IPv4 address.
The spreadsheet tells the story better than I can with words, so take a look at this screenshot of it, with the update to show how the #GuLoader threat actors have adopted this method. Basically they use the hexadecimal value for the first of the four IPv4 octets, and then the decimal conversion value for the final three octets of the IPv4 address. It's very clever, because there still isn't a very strong understanding of this low-level way that network stacks interpret IPv4 addresses. Apparently PowerShell does interpret it correctly.
Just another weirdness and we haven't even gotten to the malware, itself.
#GuLoader #Remcos #maltax #malware #dotlessIP #retroCVE
6/
-
What's up with that #GuLoader URL?
The command uses a URL format that looks like a hexadecimal value, a dot, and then a decimal number.
It turns out that this is a variation of the so-called #dotless IP address format.
Back in 1999, there was a vulnerability in Internet Explorer where someone figured out this very odd bug. CVE-1999-1087 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1087 aka MS98-016) describes this bug and the strange formatting of the URL.
Back then, @threatresearch created a little Excel spreadsheet that shows how to do this conversion. In essence, a dotless IP address is the decimal representation of a hexadecimal representation of the four octets in an IPv4 address.
The spreadsheet tells the story better than I can with words, so take a look at this screenshot of it, with the update to show how the #GuLoader threat actors have adopted this method. Basically they use the hexadecimal value for the first of the four IPv4 octets, and then the decimal conversion value for the final three octets of the IPv4 address. It's very clever, because there still isn't a very strong understanding of this low-level way that network stacks interpret IPv4 addresses. Apparently PowerShell does interpret it correctly.
Just another weirdness and we haven't even gotten to the malware, itself.
#GuLoader #Remcos #maltax #malware #dotlessIP #retroCVE
6/
-
What's up with that #GuLoader URL?
The command uses a URL format that looks like a hexadecimal value, a dot, and then a decimal number.
It turns out that this is a variation of the so-called #dotless IP address format.
Back in 1999, there was a vulnerability in Internet Explorer where someone figured out this very odd bug. CVE-1999-1087 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1087 aka MS98-016) describes this bug and the strange formatting of the URL.
Back then, @threatresearch created a little Excel spreadsheet that shows how to do this conversion. In essence, a dotless IP address is the decimal representation of a hexadecimal representation of the four octets in an IPv4 address.
The spreadsheet tells the story better than I can with words, so take a look at this screenshot of it, with the update to show how the #GuLoader threat actors have adopted this method. Basically they use the hexadecimal value for the first of the four IPv4 octets, and then the decimal conversion value for the final three octets of the IPv4 address. It's very clever, because there still isn't a very strong understanding of this low-level way that network stacks interpret IPv4 addresses. Apparently PowerShell does interpret it correctly.
Just another weirdness and we haven't even gotten to the malware, itself.
#GuLoader #Remcos #maltax #malware #dotlessIP #retroCVE
6/
-
What's up with that #GuLoader URL?
The command uses a URL format that looks like a hexadecimal value, a dot, and then a decimal number.
It turns out that this is a variation of the so-called #dotless IP address format.
Back in 1999, there was a vulnerability in Internet Explorer where someone figured out this very odd bug. CVE-1999-1087 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1087 aka MS98-016) describes this bug and the strange formatting of the URL.
Back then, @threatresearch created a little Excel spreadsheet that shows how to do this conversion. In essence, a dotless IP address is the decimal representation of a hexadecimal representation of the four octets in an IPv4 address.
The spreadsheet tells the story better than I can with words, so take a look at this screenshot of it, with the update to show how the #GuLoader threat actors have adopted this method. Basically they use the hexadecimal value for the first of the four IPv4 octets, and then the decimal conversion value for the final three octets of the IPv4 address. It's very clever, because there still isn't a very strong understanding of this low-level way that network stacks interpret IPv4 addresses. Apparently PowerShell does interpret it correctly.
Just another weirdness and we haven't even gotten to the malware, itself.
#GuLoader #Remcos #maltax #malware #dotlessIP #retroCVE
6/
-
What's up with that #GuLoader URL?
The command uses a URL format that looks like a hexadecimal value, a dot, and then a decimal number.
It turns out that this is a variation of the so-called #dotless IP address format.
Back in 1999, there was a vulnerability in Internet Explorer where someone figured out this very odd bug. CVE-1999-1087 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1087 aka MS98-016) describes this bug and the strange formatting of the URL.
Back then, @threatresearch created a little Excel spreadsheet that shows how to do this conversion. In essence, a dotless IP address is the decimal representation of a hexadecimal representation of the four octets in an IPv4 address.
The spreadsheet tells the story better than I can with words, so take a look at this screenshot of it, with the update to show how the #GuLoader threat actors have adopted this method. Basically they use the hexadecimal value for the first of the four IPv4 octets, and then the decimal conversion value for the final three octets of the IPv4 address. It's very clever, because there still isn't a very strong understanding of this low-level way that network stacks interpret IPv4 addresses. Apparently PowerShell does interpret it correctly.
Just another weirdness and we haven't even gotten to the malware, itself.
#GuLoader #Remcos #maltax #malware #dotlessIP #retroCVE
6/
-
The Windows #shortcut pointed to a #PowerShell command. Obviously, because that's totally normal, right? 🙄
But the shortcut had been modified so that the Target field in its Properties sheet appeared blank.
Apparently there's a little bug in Windows. Microsoft already knows about it, because it was revealed in a blog post by researcher @[email protected] a year ago. If you mess around with a shortcut and prepend a big chunk of "space" characters, the Target field still works but the command will be hidden from the end user.
https://www.x86matthew.com/view_post?id=embed_exe_lnk
The threat actor used this exact technique.
The command executed by the Windows shortcut is a PowerShell "Invoke-WebRequest" download of a VBS.
#GuLoader #Remcos #maltax #malware
5/
-
The Windows #shortcut pointed to a #PowerShell command. Obviously, because that's totally normal, right? 🙄
But the shortcut had been modified so that the Target field in its Properties sheet appeared blank.
Apparently there's a little bug in Windows. Microsoft already knows about it, because it was revealed in a blog post by researcher @[email protected] a year ago. If you mess around with a shortcut and prepend a big chunk of "space" characters, the Target field still works but the command will be hidden from the end user.
https://www.x86matthew.com/view_post?id=embed_exe_lnk
The threat actor used this exact technique.
The command executed by the Windows shortcut is a PowerShell "Invoke-WebRequest" download of a VBS.
#GuLoader #Remcos #maltax #malware
5/
-
The Windows #shortcut pointed to a #PowerShell command. Obviously, because that's totally normal, right? 🙄
But the shortcut had been modified so that the Target field in its Properties sheet appeared blank.
Apparently there's a little bug in Windows. Microsoft already knows about it, because it was revealed in a blog post by researcher @[email protected] a year ago. If you mess around with a shortcut and prepend a big chunk of "space" characters, the Target field still works but the command will be hidden from the end user.
https://www.x86matthew.com/view_post?id=embed_exe_lnk
The threat actor used this exact technique.
The command executed by the Windows shortcut is a PowerShell "Invoke-WebRequest" download of a VBS.
#GuLoader #Remcos #maltax #malware
5/
-
The Windows #shortcut pointed to a #PowerShell command. Obviously, because that's totally normal, right? 🙄
But the shortcut had been modified so that the Target field in its Properties sheet appeared blank.
Apparently there's a little bug in Windows. Microsoft already knows about it, because it was revealed in a blog post by researcher @[email protected] a year ago. If you mess around with a shortcut and prepend a big chunk of "space" characters, the Target field still works but the command will be hidden from the end user.
https://www.x86matthew.com/view_post?id=embed_exe_lnk
The threat actor used this exact technique.
The command executed by the Windows shortcut is a PowerShell "Invoke-WebRequest" download of a VBS.
#GuLoader #Remcos #maltax #malware
5/
-
The Windows #shortcut pointed to a #PowerShell command. Obviously, because that's totally normal, right? 🙄
But the shortcut had been modified so that the Target field in its Properties sheet appeared blank.
Apparently there's a little bug in Windows. Microsoft already knows about it, because it was revealed in a blog post by researcher @[email protected] a year ago. If you mess around with a shortcut and prepend a big chunk of "space" characters, the Target field still works but the command will be hidden from the end user.
https://www.x86matthew.com/view_post?id=embed_exe_lnk
The threat actor used this exact technique.
The command executed by the Windows shortcut is a PowerShell "Invoke-WebRequest" download of a VBS.
#GuLoader #Remcos #maltax #malware
5/
-
We did get a copy of the original Zip archive from the #MDR investigation. The attacker (or the cloud provider) had already pulled down the file by the time we got to it but the customer still had a copy. We then began looking for similar files on OSINT sources and found a bunch more.
The Zip files contained two files, each. One is a Windows #shortcut file, and the other was a benign file.
The benign file was an MP3 recording of a live music performance - a file that sounds like someone playing an Oud, the stringed instrument similar to a lute used widely in the middle east. (If any musical aficionados can confirm the instrument or identify the song, reach out to @threatresearch and let him know.)
We've uploaded the recording here: http://sndup.net/dh43
But although the file was legitimately an MP3, you can see they were named with the wrong file suffix. If you double-click the benign file, Windows says it can't open it. So it encourages the recipient to double-click the other icon, the one that looks like it's supposed to be a PDF document.
It wasn't a PDF document.
4/
-
We did get a copy of the original Zip archive from the #MDR investigation. The attacker (or the cloud provider) had already pulled down the file by the time we got to it but the customer still had a copy. We then began looking for similar files on OSINT sources and found a bunch more.
The Zip files contained two files, each. One is a Windows #shortcut file, and the other was a benign file.
The benign file was an MP3 recording of a live music performance - a file that sounds like someone playing an Oud, the stringed instrument similar to a lute used widely in the middle east. (If any musical aficionados can confirm the instrument or identify the song, reach out to @threatresearch and let him know.)
We've uploaded the recording here: http://sndup.net/dh43
But although the file was legitimately an MP3, you can see they were named with the wrong file suffix. If you double-click the benign file, Windows says it can't open it. So it encourages the recipient to double-click the other icon, the one that looks like it's supposed to be a PDF document.
It wasn't a PDF document.
4/
-
We did get a copy of the original Zip archive from the #MDR investigation. The attacker (or the cloud provider) had already pulled down the file by the time we got to it but the customer still had a copy. We then began looking for similar files on OSINT sources and found a bunch more.
The Zip files contained two files, each. One is a Windows #shortcut file, and the other was a benign file.
The benign file was an MP3 recording of a live music performance - a file that sounds like someone playing an Oud, the stringed instrument similar to a lute used widely in the middle east. (If any musical aficionados can confirm the instrument or identify the song, reach out to @threatresearch and let him know.)
We've uploaded the recording here: http://sndup.net/dh43
But although the file was legitimately an MP3, you can see they were named with the wrong file suffix. If you double-click the benign file, Windows says it can't open it. So it encourages the recipient to double-click the other icon, the one that looks like it's supposed to be a PDF document.
It wasn't a PDF document.
4/
-
We did get a copy of the original Zip archive from the #MDR investigation. The attacker (or the cloud provider) had already pulled down the file by the time we got to it but the customer still had a copy. We then began looking for similar files on OSINT sources and found a bunch more.
The Zip files contained two files, each. One is a Windows #shortcut file, and the other was a benign file.
The benign file was an MP3 recording of a live music performance - a file that sounds like someone playing an Oud, the stringed instrument similar to a lute used widely in the middle east. (If any musical aficionados can confirm the instrument or identify the song, reach out to @threatresearch and let him know.)
We've uploaded the recording here: http://sndup.net/dh43
But although the file was legitimately an MP3, you can see they were named with the wrong file suffix. If you double-click the benign file, Windows says it can't open it. So it encourages the recipient to double-click the other icon, the one that looks like it's supposed to be a PDF document.
It wasn't a PDF document.
4/
-
We did get a copy of the original Zip archive from the #MDR investigation. The attacker (or the cloud provider) had already pulled down the file by the time we got to it but the customer still had a copy. We then began looking for similar files on OSINT sources and found a bunch more.
The Zip files contained two files, each. One is a Windows #shortcut file, and the other was a benign file.
The benign file was an MP3 recording of a live music performance - a file that sounds like someone playing an Oud, the stringed instrument similar to a lute used widely in the middle east. (If any musical aficionados can confirm the instrument or identify the song, reach out to @threatresearch and let him know.)
We've uploaded the recording here: http://sndup.net/dh43
But although the file was legitimately an MP3, you can see they were named with the wrong file suffix. If you double-click the benign file, Windows says it can't open it. So it encourages the recipient to double-click the other icon, the one that looks like it's supposed to be a PDF document.
It wasn't a PDF document.
4/
-
In the case of this infection, the attacker didn't send anything malicious until the person they contacted replied to this benign "introduction"/solicitation email. It was smart because it kept them off the radar for our #spam traps.
The link pointed to a file hosted in a large cloud storage provider. The file was a password-protected Zip archive, and all the archives we came across used the same password: Fresh@123
The Zip's contents were pretty weird, and then it got weirder.
3/
-
In the case of this infection, the attacker didn't send anything malicious until the person they contacted replied to this benign "introduction"/solicitation email. It was smart because it kept them off the radar for our #spam traps.
The link pointed to a file hosted in a large cloud storage provider. The file was a password-protected Zip archive, and all the archives we came across used the same password: Fresh@123
The Zip's contents were pretty weird, and then it got weirder.
3/
-
In the case of this infection, the attacker didn't send anything malicious until the person they contacted replied to this benign "introduction"/solicitation email. It was smart because it kept them off the radar for our #spam traps.
The link pointed to a file hosted in a large cloud storage provider. The file was a password-protected Zip archive, and all the archives we came across used the same password: Fresh@123
The Zip's contents were pretty weird, and then it got weirder.
3/
-
In the case of this infection, the attacker didn't send anything malicious until the person they contacted replied to this benign "introduction"/solicitation email. It was smart because it kept them off the radar for our #spam traps.
The link pointed to a file hosted in a large cloud storage provider. The file was a password-protected Zip archive, and all the archives we came across used the same password: Fresh@123
The Zip's contents were pretty weird, and then it got weirder.
3/
-
In the case of this infection, the attacker didn't send anything malicious until the person they contacted replied to this benign "introduction"/solicitation email. It was smart because it kept them off the radar for our #spam traps.
The link pointed to a file hosted in a large cloud storage provider. The file was a password-protected Zip archive, and all the archives we came across used the same password: Fresh@123
The Zip's contents were pretty weird, and then it got weirder.
3/
-
@SophosXOps First found out about the campaign when one of the affected companies reached out to us about alerts they were seeing on their dashboard. The #Sophos #MDR team began to investigate, found the #malware immediately, collected evidence, and removed it. It would have been a fairly boring, mundane story of #malware cleanup but then we found out about the way the target was initially infected.
The threat actor sent a moderately generic, entirely benign email to the tax preparation firm asking them if they're taking on new clients. There was no malicious attachment or link, just a conversational, chatty email from the kind of person who might, actually, be a prospective client to a tax preparer.
2/
-
@SophosXOps First found out about the campaign when one of the affected companies reached out to us about alerts they were seeing on their dashboard. The #Sophos #MDR team began to investigate, found the #malware immediately, collected evidence, and removed it. It would have been a fairly boring, mundane story of #malware cleanup but then we found out about the way the target was initially infected.
The threat actor sent a moderately generic, entirely benign email to the tax preparation firm asking them if they're taking on new clients. There was no malicious attachment or link, just a conversational, chatty email from the kind of person who might, actually, be a prospective client to a tax preparer.
2/
-
@SophosXOps First found out about the campaign when one of the affected companies reached out to us about alerts they were seeing on their dashboard. The #Sophos #MDR team began to investigate, found the #malware immediately, collected evidence, and removed it. It would have been a fairly boring, mundane story of #malware cleanup but then we found out about the way the target was initially infected.
The threat actor sent a moderately generic, entirely benign email to the tax preparation firm asking them if they're taking on new clients. There was no malicious attachment or link, just a conversational, chatty email from the kind of person who might, actually, be a prospective client to a tax preparer.
2/
-
@SophosXOps First found out about the campaign when one of the affected companies reached out to us about alerts they were seeing on their dashboard. The #Sophos #MDR team began to investigate, found the #malware immediately, collected evidence, and removed it. It would have been a fairly boring, mundane story of #malware cleanup but then we found out about the way the target was initially infected.
The threat actor sent a moderately generic, entirely benign email to the tax preparation firm asking them if they're taking on new clients. There was no malicious attachment or link, just a conversational, chatty email from the kind of person who might, actually, be a prospective client to a tax preparer.
2/
-
@SophosXOps First found out about the campaign when one of the affected companies reached out to us about alerts they were seeing on their dashboard. The #Sophos #MDR team began to investigate, found the #malware immediately, collected evidence, and removed it. It would have been a fairly boring, mundane story of #malware cleanup but then we found out about the way the target was initially infected.
The threat actor sent a moderately generic, entirely benign email to the tax preparation firm asking them if they're taking on new clients. There was no malicious attachment or link, just a conversational, chatty email from the kind of person who might, actually, be a prospective client to a tax preparer.
2/