Beware of phishing emails disguised as quote requests

Beware of phishing emails disguised as quote requests

Recently, the AhnLab SEcurity intelligence Center (ASEC) confirmed that phishing emails disguised as requests for project quotes are being circulated. The email body is disguised as a request to submit a quote for discussing the project budget and prompts recipients to download an attached compressed file for verification.

 

[Figure 1] Phishing email body

 

When a user downloads and decompresses the attached compressed file, a VBScript file is hidden inside, as shown in [Figure 2]. This VBScript first checks for the presence of the legitimate system file notepad.Exe, then extracts the characters ‘s’ and ‘l’ from the file’s hexadecimal data. The extracted characters are used to construct the final executable file name, “powershell,” which is an obfuscation technique designed to make analysis and detection more difficult. The PowerShell script that runs afterward restores the obfuscated code by replacing arbitrary tokens with actual characters and symbols. The identified key substitution rules are as follows.

 

Obfuscation Tokens Substitution Character
Axis S
Longar O
Hoimulz $
Humoled C

[Table 1] Substitution Rules

 

In this way, the threat actor repeatedly performs token-based string substitution to reconstruct the original PowerShell Command and then executes malicious behavior.

 

[Figure 2] RAR compressed file

[Figure 3] PowerShell.Exe string generation

[Figure 4] Excerpt from VBScript-2

 

The executed PowerShell script decodes the obfuscated string inside it in the manner shown in [Figure 5], and then executes the reconstructed command.

 

[Figure 5] String decryption method

 

It then connects to the threat actor’s C2 server to download an additional payload; the downloaded data is organized into three sections based on offsets, as shown in [Table 2] and [Figure 7].

 

Additional Payload Download C2

  • Hxxp://drive.Google[.]Com/uc?Export=download&id=1ge2-tdX0-_A6ZU6FDMEFynhz1m0L5lHm

 

[Figure 6] Additional Payload Download

Offset Range Components Size
0X00000–0x01C98 Loader 7,321 Bytes
0X01C99–0x2267F Payload 133,607 Bytes
0X22680–0x2714D Secondary PowerShell payload 19,150 Bytes

[Table 2] Additional Payload Components

[Figure 7] Additional Payload Structure

 

The downloaded payload is stored in the %APPDATA%\Maleic.For Path, and among the three sections, the secondary PowerShell payload is the first to execute in memory. Subsequently, this script initiates the execution of the loader and payload.

 

[Figure 8] Execution of the Secondary PowerShell Payload

 

The executed secondary PowerShell payload creates a ShellWindows COM object to bypass UAC. It then indirectly uses the ShellExecute Path of explorer.Exe to launch a new PowerShell process and execute subsequent commands with privilege escalation.

 

ShellWindows CLSID

  • {9BA05972-F6A8-11CF-A442-00A0C90A8F39}

 

[Figure 9] UAC Bypass

 

After privilege escalation, the loader section is extracted from the %APPDATA%\Maleic.For file and loaded into memory. At this point, the Payload section is passed as an argument to the loader; the loader decrypts it using an XOR operation and executes it in memory.

 

[Figure 10] Execution of the Loader Section

[Figure 11] Payload Decryption and Execution

 

The decrypted and executed payload downloads Remcos RAT—the final piece of malware—from the C2 server into memory. It then decrypts this and injects it into the legitimate process MicrosoftEdgeUpdate.Exe to execute it.

 

Remcos RAT Download C2

  • Hxxp://drive.Google[.]Com/uc?Export=download&id=1yJZysgMU6LZmCZtpko0y1uO1jsbYDIRO

 

[Figure 12] To download and execute the final malware

 

The Remcos RAT, once executed, is malware that receives and executes remote commands on the infected system. It collects system and user information through various functions, such as keylogging, screen capture, and file manipulation. The collected information and execution results are transmitted externally via communication with the C2 server.

 

Remcos RAT C2

  • 102.220.160[.]104:2404

 

[Figure 13] Remcos RAT in final execution

 

Response Guide

 

1. Verify the Sender

  • Verify that the sender’s email address belongs to an official domain.

2. Check Hyperlinks and Attachments

  • If the email prompts you to click on an image attached to the body of the message, check the linked URL first before clicking. Suspicious URLs often redirect to legitimate pages via intermediate paths rather than going directly to the official page, so examine them carefully. Additionally, if there are attachments, check for suspicious file extensions (.Exe, .Vbs, .Js, etc.).

3. Be Cautious When Entering Sensitive Information

  • If you are asked to provide sensitive information, such as login credentials, always verify that the page’s URL corresponds to the official website before entering any information. If the page is not official, it is highly likely that the URL is suspicious, so caution is required. In particular, check the page’s security certification (HTTPS, padlock icon) before entering sensitive information, and never enter any information if you have any doubts.

MD5

af87821d3cb4f1d72bfb8002437593ec
URL

https[:]//drive[.]google[.]com/uc?export=download&id=1ge2-tdX0-_A6ZU6FDMEFynhz1m0L5lHm
https[:]//drive[.]google[.]com/uc?export=download&id=1yJZysgMU6LZmCZtpko0y1uO1jsbYDIRO

Gain access to related IOCs and detailed analysis by subscribing to AhnLab TIP. For subscription details, click the banner below.