'PhantomBlu' Cyberattackers Backdoor Microsoft Office Users via OLE (www.darkreading.com)
from kid@sh.itjust.works to cybersecurity@sh.itjust.works on 20 Mar 2024 10:46
https://sh.itjust.works/post/16522947

#cybersecurity

threaded - newest

kid@sh.itjust.works on 20 Mar 2024 10:56 next collapse

IoCs:

IOCs Hashes (SHA-256) Email – 16e6dfd67d5049ffedb8c55bee6ad80fc0283757bc60d4f12c56675b1da5bf61

Docx – 1abf56bc5fbf84805ed0fbf28e7f986c7bb2833972793252f3e358b13b638bb1

Injected ZIP – 95898c9abce738ca53e44290f4d4aa4e8486398de3163e3482f510633d50ee6c

LNK file – d07323226c7be1a38ffd8716bc7d77bdb226b81fd6ccd493c55b2711014c0188

Final ZIP – 94499196a62341b4f1cd10f3e1ba6003d0c4db66c1eb0d1b7e66b7eb4f2b67b6 26/64

Client32.exe – 89f0c8f170fe9ea28b1056517160e92e2d7d4e8aa81f4ed696932230413a6ce1 26/73

URLs and Hostnames yourownmart[.]com/solar[.]txt

firstieragency[.]com/depbrndksokkkdkxoqnazneifidmyyjdpji[.]txt

yourownmart[.]com

firstieragency[.]com

parabmasale[.]com

tapouttv28[.]com

IP Addresses 192[.]236[.]192[.]48

173[.]252[.]167[.]50

199[.]188[.]205[.]15

46[.]105[.]141[.]54

Others Message ID contains: “sendinblue[.]com”

Return Path contains: “sender-sib[.]com”

Source

magikmw@lemm.ee on 20 Mar 2024 11:33 collapse

I mean, the delivery method isn’t exactly trivial. Open email, download, use provided password, enable editing, then click on a print image…

Yes, there are users that will do it, but every step is a checkpoint.