

Rewterz Threat Alert: Fresher Phishing Campaigns Targeting Pakistani Bank Employees
January 29, 2019
Rewterz Threat Alert – Phishing Awareness For Employees and Customers of the Banking Industry
January 30, 2019
Rewterz Threat Alert: Fresher Phishing Campaigns Targeting Pakistani Bank Employees
January 29, 2019
Rewterz Threat Alert – Phishing Awareness For Employees and Customers of the Banking Industry
January 30, 2019SEVERITY: Medium
CATEGORY: Phishing
ANALYSIS SUMMARY
A campaign distributing both Ursnif malware and GrandCrab ransomware via malicious Word documents attached to phishing emails. The Word documents contained a VBS macro that executes a base64 encoded PowerShell script. The PowerShell script is used to retrieve the files associated with the GrandCrab and Ursnif infections. The first payload that is downloaded and executed is a PowerShell command used to download an additional PowerShell script. This additional PowerShell script contains a base64 encoded PE file which it injects into memory for execution. This PE file was identified to be a variant of the GrandCrab ransomware. The second payload that is download and executed via the VBS macro is the Ursnif executable, which is used for malicious activities such as gathering system information and harvesting credentials.
Impact
Leakage of system information
Loss of credentials
INDICATORS OF COMPROMISE
URLs
bevendbrec[.]com
iscondisth[.]com
Malware Hash (MD5/SHA1/SH256)
c064f6f047a4e39014a29c8c95526c3fe90d7bcea5ef0b8f21ea306c27713d1f
d6c53d9341dda1252ada3861898840be4d669abae2b983ab9bf5259b84de7525
0a3f915dd071e862046949885043b3ba61100b946cbc0d84ef7c44d77a50f080
Remediation
Block all URL’s and IoC’s at your respective controls.
Ensure anti virus software and associated files are up to date.
Always be suspicious about emails sent to users from unknown senders.