Security Alert: Booking.Com Fake Emails Infect Computers with Sodinokibi Ransomware
#1
Exclamation 
Quote:
[Image: heimdal-logo.svg]

Opening attachments will download and run a dangerous GandCrab strain

A new spam campaign pretending to be from Booking.com is now targeting users. The emails carry a document containing macro code. If someone clicks on the document, opens it, and allows the execution of the macro code, a loader will be spawned.

This will download and run ransomware of the Sodinokibi class.

How does the fake Booking.com email that infects you with ransomware work?

Below you can see how a Sodinokibi ransomware email looks like:

Quote:

From: [Compromised email account]

Subject:

Booking.]com – New booking! (1571165841, Monday, 17 June 2019)

Attached:

[name of recipient].doc

If one clicks on the content of the document, the embedded object will decode the file “ms-word.exe”.

Once the file is run, it will spawn a shell that will run the ransomware’s loader, as you can see below:

[Image: Sodinokibi1806.png]

Similar to other ransomware families, the spawned shell will start with deleting shadow in order to make the restoration of the machine more complicated:

“C:\Windows\System32\cmd.exe” /c vssadmin.exe Delete Shadows /All /Quiet & bcdedit /set {default} recoveryenabled No & bcdedit /set {default} bootstatuspolicy ignoreallfailures.

The payload is difficult to be analyzed since the loader is packed with a custom packer.

The packer is different from variant to variant. But what they all have in common is that they always use a PE overwrite technique.

Then, it will connect to the following URL, from which it will run the main component (sanitized by CSIS) http://btta[.]xyz/hoja.exe.
Continue Reading
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.6.2 Fixed cust...Kool — 12:18
Mozilla Firefox Browser 151.0.3
Mozilla Firefox Br...harlan4096 — 12:05
Intel lists Xe3p GPU architecture for “N...
Xe3P also listed f...harlan4096 — 06:18
NVIDIA announced RTX Spark chip for Wind...
NVIDIA confirms RT...harlan4096 — 06:17
AMD News - COMPUTEX 2026
AMD details Fidelity...harlan4096 — 06:16

[-]
Birthdays
Today's Birthdays
avatar (51)nteriageda
Upcoming Birthdays
avatar (42)tapedDow
avatar (48)BrantgoG
avatar (50)eapedDow
avatar (47)Carlosskake
avatar (49)rapedDow
avatar (44)Johnsonsyday
avatar (49)Groktus
avatar (41)efodo
avatar (39)Tedscolo
avatar (46)brakasig
avatar (51)smudloquask
avatar (46)benchJem
avatar (45)JamesReshy
avatar (47)Francisemefe
avatar (40)leoniDup
avatar (39)Patrizaancem
avatar (39)biobdam
avatar (42)zacforat
avatar (47)NemrokReks
avatar (50)Jasoncedia
avatar (38)Barrackleve
avatar (40)Julioagopy
avatar (50)aolaupitt2558
avatar (48)vadimTob
avatar (38)leannauu4
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu
avatar (32)horancos

[-]
Online Staff
There are no staff members currently online.

>