The TA505 APT hacker group is spreading a new variant of the ServHelper malware via Excel 4.0, aiming to open a "backdoor" that will allow it to gain access and steal sensitive information.
TA505 hackers have been involved in various attacks, such as the Dridex banking Trojan and Locky ransomware.
The TA505 group mainly targets institutions, organizations, banks, businesses and restaurants.
In this case, hackers use the Excel 4.0 macro Dropper to deliver the ServHelper Backdoor and payload.
How does the system get infected?
Initially, the malicious Excel spreadsheet is delivered via malspam emails. If the target user opens the document, the Excel 4.0 macro is executed and msiexec.exe is called to download and execute the ServHelper payload.
The ServHelper installer has a valid digital signature.
Once the malicious code is executed, a DLL file, which is included in the installer, will be installed in the following path: \%TEMP%\xmlparse.dll. Then, the function named “sega”, which is included in the malicious DLL, is called via rundll32.exe.
The malware will then run a base64 encoded PowerShell script (which is included in xmlparse.dll as a resource) at the following path \%TEMP%\enu1.ps1.
Later, the malware will run a base64 encoded PowerShell script checking whether a machine is part of a domain. It also checks whether the user has administrator privileges or is a member of the administrators group.
Finally, ServHelper communicates with its C2 to receive commands from the attacker.
The TA505 group poses a significant threat, as it constantly develops sophisticated malware for various purposes.
Indications that there is a risk
Excel 4.0 macro Dropper
63522e00181e6b8d9ae8bfd51f7df8f8ebd0f42323e22047269df9c7a71c9b6d
NSIS Payloads
e0323064f2561ae02f9efae418aeaf433b3fe0e6e3a640a9c46ec404d4563de1 302aa690ae61d36769ecdaa3d23ac8fb167e80aed2fe5dbc8938f7b75c655a01
ServHelper core DLL
bee3b2710f7e874ce05e6b8b45cc20e021b9c00ee337238598e71e7315128333 2f827084ecc300aea0c84cba8872c9a34e6afce56eea454d74f4dd3144301a2d
Encoded reconnaissance PowerShell script
da7465f14cd8a934668f59974e8836e02a9b1ff948bfe964040b840ab61697dc da7465f14cd8a934668f59974e8836e02a9b1ff948bfe964040b840ab61697dc
