SUCURILABS
SUCURILABS
BlogAbout us

Threat Insights 0x25: AdwinRAT disguised as invoice

September 6, 2024

AdwinRAT delivered through email attachments

Email 1

  • Rating: ★★★★☆
  • Date: 2024-09-05
  • Objective: Malware
  • Analyst: José Morim

The email is disguised as an invoice but has a far more malicious intent. Its true purpose is to deceive the recipient into opening the attached file, which contains a harmful executable. If the recipient runs the file, it installs AdwinRAT on their system, all while they believe they are managing a legitimate business request:

Page 1

The attacker’s primary objective is to manipulate the victim into executing the malicious payload, thereby infecting their system with malware. This allows the attacker to covertly collect sensitive information and credentials, compromising the victim’s security.

Portugal tax authority impersonation

Email 2

  • Rating: ★★★☆☆
  • Date: 2024-09-06
  • Objective: Personal identification harvesting
  • Analyst: José Morim

In this phishing email, the attacker tries to trigger a sense of panic in the recipient by impersonating the local tax authority, pressuring the recipient to click a link to see their tax recalculation request. However, this link is deceptive and leads to a malicious website designed to harvest personal information.

Payment refunded!

Email 3

  • Rating: ★★★☆☆
  • Date: 2024-09-03
  • Objective: Malware
  • Analyst: José Morim

The email appears to be a payment refund notification, but its actual intent is much more malicious. It is designed to deceive the recipient into downloading and executing a file that contains harmful malware:

Page 3

Once the file is executed, it installs the malware on the recipient's system, all under the guise of handling a legitimate business transaction.

IOCs

TYPEIOC
FILE53913469bad501d21ec745362fb23e9c8ba32d9eac0b99adcc561d96da563591
HOST80[.]190[.]85[.]84
URLhxxps[://]www[.]mediafire[.]com/file_premium/z3bi56brp8muojj/Fatura[.]pdf_-_[.]jar/file
URLhxxps[://]app-kontor[.]online/
URLhxxps[://]inboxsender[.]gxsearch[.]club/PT2/serial[.]php
URLhxxps[://]roncluv[.]com/pt2/arquivos/bbnc[.]html
URLhxxps[://]roncluv[.]com/pt2/arquivos/download[.]php

Keep up with threat insights

Threat Insights is a weekly series where we present you with analysis from samples we collect. Follow us on social media for the latest feed and cybersecurity content. Stay informed and stay safe!


Get more insights like this

  • Follow us on social media to get a weekly update of our latest content, and don't worry—we won't spam your feed ;)
  • Join our private beta and get a sneak peek at how your team will improve their security posture.


Copyright © 2024-2025 SUCURILABS Lda. All rights reserved.