October 27, 2020 Lieying Lab Comments 0 Comment 6,330 views
Summary
Recently, the Threat Intelligence Center monitored attack samples disguised as documents, with decoy content such as “prosecutor's office ruling” and “Taiwan-funded account handover.” The core remote-control program used the open-source AsyncRAT. Analysis of the samples found that the callback domain resolved to an IP address in Taiwan.
Analysis
We captured multiple malicious programs, including 李娟.Docx.exe and 黃.exe, disguised with Word icons or content.
| MD5 | Sample Name |
|---|---|
| 32f8b3e8d4c0c89ac03192ef9db6d1e2 | 李娟.Docx.exe |
| 45af1843f7d26ef2fe41ca447fcaa8a2 | 李娟.Docx.exe |
| 60a763d7a45adfb76cab058765a38994 | 李娟.Docx.exe |
| 0edb41acc19b43a6fca9ec0299a1e495 | 黃.exe |
| 57c05e7dc30fa660fbe7aaa1a660799c | 更換新S-docx.exe |
| 633462867d0371745692a62c96dcfddf | image.exe |
| …… |
Take 李娟.Docx.exe (32f8b3e8d4c0c89ac03192ef9db6d1e2) as an example for analysis.
The sample was disguised with a Word icon and was a Loader written in C#.

The sample dropped a BAT script and a decoy document into the temp directory, executed the BAT file, and opened the decoy document.

The document's decoy content was a prosecutor's office ruling notice.

The document properties show that it was last modified on October 14, 2020, and the dates appearing in the document content indicate that this attack activity emerged recently.

The BAT program executes PowerShell.

PowerShell accesses and loads remote content for execution. The remote content was hosted on minpic[.]de at the following remote address:
https://www.minpic[.]de/k/b33p/nmy0x/

The content was the final payload, the open-source C# remote-access program AsyncRAT.

It connected back to andy1688.ddns[.]net.
| Historical Resolution IP | Geolocation | Earliest Known Resolution |
|---|---|---|
| 123.240.122.235 | China-Taiwan-Taichung (Taiwan Broadband Communications Consulting Co., Ltd.) | 2020-10-07 |
| 123.110.29.249 | China-Taiwan-Taichung (Taiwan Broadband Communications Consulting Co., Ltd.) | 2020-08-27 |
Related Analysis
The decoy document content of 黄.exe, which was also disguised with a Word icon, was likewise related to a prosecutor's office ruling.

The decoy document content of the 更換新S-docx.exe program was a prosecutor's office arrest warrant.

The Image.exe program was disguised as image content related to “money laundering.”

The final payload also used AsyncRAT.
Conclusion
The current situation is relatively tense, and this batch of captured samples is highly suspicious and warrants attention.
Leveraging its core data capabilities, the DBAPPSecurity Threat Intelligence Center provides professional capabilities such as threat-intelligence data and threat-intelligence detection.
IOC
32f8b3e8d4c0c89ac03192ef9db6d1e2
45af1843f7d26ef2fe41ca447fcaa8a2
60a763d7a45adfb76cab058765a38994
0edb41acc19b43a6fca9ec0299a1e495
633462867d0371745692a62c96dcfddf
de312dc399c6861874bd828ff65be880
2120e702d60bf4c8b73e9cc898682a34
e832269f556af0c2343a7b10d4882525
7424c0241b2e88c4b2cefa14f9646341
c9cf97cd924c62325c623a7c74ad9dc0
c05de8d42b847e1956741c2579a54027
3fababcd18fd8a986676ea55cdc16d14
4f6c0849b1ec07b84eb1fccbdc3a7d2d
53f3a5d5989e66e323a2e887865b100c
57c05e7dc30fa660fbe7aaa1a660799c
6e5629dc23e884cbe202e0bd33334a9c
54aa0b147daedae52e1ae07a85aa430d
953d45534349a9c3ce2eeb3f43da4eb9
c50748b4f8ef1ad46044de5fe49cbae0
c3e2758dc78fe4c04cf9c469bb1d023d
05d2450b18bfe230c118653700dc503d
834be313665b88c7315e74c7f2179d25
6b745df2a6227c5898dc1490babd1841
8ef5c3930ef7ccec2862a765e992fdfd
2f404e225bdc919bd4cf407ce1a3b2bd
2748cfb72696852c00c381e53a14342f
andy1688.ddns[.]net
123.240.122[.]235
123.110.29[.]249