Beware of Phishing Emails That Disguise Themselves as Project Material Purchase Requests
Recently, the AhnLab SEcurity intelligence Center (ASEC) identified a case of phishing emails that disguise themselves as project material purchase request forms. These emails impersonate employees of a specific company in Korea and trick recipients into opening a malicious XLS file attached to the email, which is disguised as a project material purchase request form.

[Figure 1] Body of the phishing email
When a user downloads and opens the attached XLS file, the contents of a legitimate project material purchase request form are displayed, as shown in [Figure 2]. This serves as a decoy document designed to lower the user’s suspicion. However, the document contains the CVE-2017-0199 vulnerability, which exploits OLE objects. This vulnerability is a remote code execution (RCE) flaw that exploits the OLE2Link feature in Microsoft Office; when a user opens the document, it automatically accesses an external URL to download and execute additional malicious files (such as HTA files). In this case, it downloads and executes a malicious HTA file from the C2 server listed below.
HTA Download C2
- Hxxp://172.245.209[.]133/70/Weprovideforbesthingstocomebackgoodthings.Hta

[Figure 2] Malicious XLS file disguised as a lure

[Figure 3] CVE-2017-0199 vulnerability
Once the malicious HTA file is downloaded from the C2 server and executed, it uses the Win32_Process.Create() method of WMI to execute an obfuscated PowerShell script in the background.

[Figure 4] Part of the malicious HTA script before obfuscation

[Figure 5] Part of the malicious HTA script after obfuscation
The decrypted contents of the executed PowerShell script are shown in [Figure 6]. This script downloads a steganographically embedded PNG file from an additional C2 server and then extracts a Base64-encoded .NET loader-type malware using the strings “IN-” and “-inl” as markers. It then decrypts this payload, loads it into memory, and executes it. At this point, the loader operates by receiving the C2 server address—from which it will download the Remcos RAT—as an argument value.
Steganography PNG Download C2
- Hxxp://muddy-sound-e0cd.Nodetectonn.Workers[.]Dev/HIsPq
Remcos RAT Download C2
- Hxxp://172.245.209.133/70/Img_201031[.]Png

[Figure 6] Malicious PowerShell script

[Figure 7] PNG with steganography applied

[Figure 8] Base64 data embedded in the steganographic PNG
Ultimately, the Remcos RAT is malware that receives and executes remote commands on an infected system; it collects system and user information through various functions, such as keylogging, screen capture, and file manipulation. The collected information and execution results are transmitted externally via communication with the C2 server.
Remcos RAT C2
- Blessedongrace.Duckdns[.]Org:19700

[Figure 9] The Remcos RAT in final execution
Response Guide
1. Verify the Sender
- Verify that the sender’s email address uses an official domain.
2. Check Hyperlinks and Attachments
- If the email body contains an image that prompts you to click on it, check the linked URL first before clicking. Suspicious URLs often lead through other paths—not the official page—before finally redirecting to a legitimate page, so you should examine them carefully. Also, if there are attachments, check for suspicious file extensions (.Exe, .Vbs, .Js, etc.).
3. Be Careful When Entering Sensitive Information
- If you are asked to provide sensitive information, such as login credentials, always verify that the page’s URL corresponds to the official website before entering any information. If the page is not official, it is highly likely to be a suspicious URL, so caution is required. In particular, always check the page’s security certification (HTTPS, padlock icon) before entering sensitive information, and never enter any information if the page appears suspicious.