Tuesday, March 4, 2025
HomeComputer SecurityBeware of Malicious Word Documents that Downloads the Ursnif Malware and GandCrab...

Beware of Malicious Word Documents that Downloads the Ursnif Malware and GandCrab Ransomware

Published on

SIEM as a Service

Follow Us on Google News

A new phishing email campaign contained a malicious word document with macros downloads and executes Ursnif malware and GandCrab ransomware.

Security researchers from Carbon Black observed the campaign in wild and roughly 180 variants detected.

The first stage of attack starts in delivering of weaponized MS word document to deliver the initial stages, according to metadata it appears the documents prepared on December 17, 2018, and continues up to January 21, 2019. Documents found embedded with VBS macros that contain 18 lines of VBScript.

The Second stage starts with the execution of PowerShell script that creates a web client instances and looks for DownloadString to communicate with C2 server and stores the data in the CommonApplicationData directory.

The attack if successful delivers multiple payloads in the infected machine, “the overall attack leverages several different approaches, which are popular techniques amongst red teamers, espionage focused adversaries, and large scale criminal campaigns,” reads Carbon Black analysis report.

GandCrab Ransomware

The first payload downloaded via the DownloadString method analyzes the system architecture of the compromised system and downloads additional payload from pastebin which is the GandCrab Variant.

The Gandcrab Ransomware is a widespread Ransomware, nowadays it evolves with newly updated futures under constant development to target various countries.

Ursnif Malware

The second payload is the Ursnif executable which harvest the system information, once executed it performs credential harvesting, gathering system and process information, and deploying additional malware samples.

Researchers observed more than 120 different Ursnif variants were hosted and the file name continiously changes in the campaign.

“While researching this campaign approximately 180 variants were located in the wild. Using the VirusTotal Graph functionality these variants could be organized into several groups that were commonly associated by either metadata or document structures.”

Ursnif campaign also spotted by the security researchers from Cisco Talos, the malicious macro contains a single command encoded with base64 and it downloads the Ursnif executable.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Progress WhatsUp Gold Path Traversal Vulnerability Exposes Systems to Remote code Execution

A newly disclosed path traversal vulnerability (CVE-2024-4885) in Progress Software’s WhatsUp Gold network monitoring...

CISA Alerts on Active Exploitation of Cisco Small Business Router Flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent warning on March...

Threat Actors Exploiting AES Encryption for Stealthy Payload Protection

Cybersecurity researchers have uncovered a surge in the use of Advanced Encryption Standard (AES)...

33.3 Million Cyber Attacks Targeted Mobile Devices in 2024 as Threats Surge

Kaspersky's latest report on mobile malware evolution in 2024 reveals a significant increase in...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Winos4.0 Malware Targets Windows Users Through Malicious PDF Files

A new wave of cyberattacks leveraging the Winos4.0 malware framework has targeted organizations in...

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has...

Squidoor: Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2

A newly identified malware, dubbed "Squidoor," has emerged as a sophisticated threat targeting government,...