Bitcoin Forum
May 06, 2024, 06:03:25 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Microsoft Excel can be used to delivered LimeRAT and install cryptominer  (Read 123 times)
Kemarit (OP)
Legendary
*
Offline Offline

Activity: 3080
Merit: 1353



View Profile
April 02, 2020, 08:17:35 AM
Merited by Baofeng (1)
 #1

According to the researcher from Mimecast:

Quote
LimeRAT Malware Exploited in the Wild
Recently, Mimecast threat intelligence researchers came across a campaign which used this Excel VelvetSweatshop encryption technique to deliver LimeRAT, a malicious remote access trojan.

In this specific attack, the cybercriminals also used a blend of other techniques in an attempt to fool anti-malware systems by encrypting the content of the spreadsheet hence hiding the exploit and payload.

Once LimeRAT has landed, the attacker has many capabilities at his or her fingertips, including delivering ransomware, a cryptominer, a keylogger, or creating a bot client.

Of course, given the general capability inherent with this Excel-based malware delivery technique, any type of malware is a good candidate for delivery, so Mimecast researchers expect to see it used in many more malicious phishing campaigns in the future. Mimecast Threat Center has alerted Microsoft to this campaign. 


Source

So be watch out of some Excel coming into your inbox that is password protected. Don't used the the default password "VelvetSweatshop" to try and unlock it, otherwise your machine are going to be compromise.

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
Transactions must be included in a block to be properly completed. When you send a transaction, it is broadcast to miners. Miners can then optionally include it in their next blocks. Miners will be more inclined to include your transaction if it has a higher transaction fee.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
Baofeng
Legendary
*
Offline Offline

Activity: 2590
Merit: 1658



View Profile
April 02, 2020, 11:56:19 AM
Last edit: April 02, 2020, 01:31:22 PM by Baofeng
 #2

Speaking of Excel, this one is a Covid-19 related them attacks, Phishing Attack Says You're Exposed to Coronavirus, Spreads Malware.

Email will tell that you need to print the attached spreadsheet.

Code:
EmergencyContact.xlsm

And when you open the attachment, it will asked you to "Enable Content" view to see the protected document. And once you enable, it will download a malware.

  • Search for and possibly steal cryptocurrency wallets.
  • Steals web browser cookies that could allow attackers to log in to sites with your account.
  • Gets a list of programs running on the computer.
  • Looks for open shares on the network with the net view /all /domain command.
  • Gets local IP address information configured on the computer.

███████████████████████
████████████████████
██████████████████
████████████████████
███▀▀▀█████████████████
███▄▄▄█████████████████
██████████████████████
██████████████████████
███████████████████████
█████████████████████
███████████████████
███████████████
████████████████████████
███████████████████████████
███████████████████████████
███████████████████████████
█████████▀▀██▀██▀▀█████████
█████████████▄█████████████
███████████████████████
████████████████████████
████████████▄█▄█████████
████████▀▀███████████
██████████████████
▀███████████████████▀
▀███████████████▀
█████████████████████████
O F F I C I A L   P A R T N E R S
▬▬▬▬▬▬▬▬▬▬
ASTON VILLA FC
BURNLEY FC
BK8?.
..PLAY NOW..
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!