Auteur Sujet: [FireEye]Dridex and Locky Return Via PDF Attachments in Latest Campaigns  (Lu 3331 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
Dridex and Locky Return Via PDF Attachments in Latest Campaigns

[html]

Dridex and Locky, two prolific malware families that made waves in
  2016 after being distributed in several high-volume spam campaigns,
  have returned after a brief hiatus. FireEye observed a decline in the
  volume of Dridex and Locky in the latter half of 2016, but we recently
  observed two new large campaigns.


 

While the PDF downloader described in this post is responsible for
  spreading both Dridex and Locky, for the purposes of this blog, we
  will be discussing the PDF downloader and the Dridex binary.


 

The larger of the two campaigns (Figure 1) involved a “payment
  receipt” theme and, according to our telemetry, primarily affected the
  insurance industry in the U.S.


 


 


 


  Figure 1: Telemetry for the larger campaign


 

In the smaller of the two campaigns (Figure 2), the attachment was
  claimed to be an alert from a printer for a scanned document. This
  campaign primarily affected the government sector in the Middle East,
  U.S., and Japan.


 


 


 


  Figure 2: Telemetry for the smaller campaign


 


  Execution Flow


 

As seen in Figure 3, at a high-level, the execution flow consists of:


 

  •     Spam campaign email containing a malicious PDF file

  •     Attached PDF file drops and executes a DOCM document

  •     Dropped document file contains a macro which launches a
        PowerShell script upon execution.

  •     PowerShell script then fetches an encrypted binary from the
        command and control (C2) server

  •     Encrypted Binary is decrypted and executed, and malicious
        payload is dropped and launched

 


 


 

Figure 3: Full Execution Flow


 


  Spam Campaign


 

We observed two patterns of subject lines used in these campaigns.
  One is Payment_XXX, where XXX refers to any random number,
  while the other one is Scanned image from MX-2600N. Figure 4
  shows sample spam emails from both campaigns.


 


 
   


 


  Figure 4: Spam Email Examples


 


  The Attachments


 

  Attached PDF File:

 

The PDF attachment contains several objects, but the most relevant
  ones are an embedded DOCM file (a macro enabled doc file) and a
  JavaScript object that drops and launches the DOCM file. Figure 5
  shows the embedded DOCM file, and Figure 6 shows a snippet of the
  JavaScript that drops the DOCM file.


 


 


Tags: