Summary:
The Researcher encountered a previously unseen dropper variant named "MidgeDropper," which exhibited a complex infection chain involving code obfuscation and sideloading. While the final payload remained elusive. The initial infection vector is suspected to be a phishing email, supported by the presence of an RAR archive named "!PENTING_LIST OF OFFICERS.rar." This archive contains two files, "Notice to Work-From-Home groups.pdf" and "062023_PENTING_LIST OF SUPERVISORY OFFICERS WHO STILL HAVE NOT REPORT.pdf.exe," which serve as decoys to lure victims into executing the malicious payload.[/subscribe_to_unlock_form]
Summary:
The Researcher encountered a previously unseen dropper variant named "MidgeDropper," which exhibited a complex infection chain involving code obfuscation and sideloading. While the final payload remained elusive. The initial infection vector is suspected to be a phishing email, supported by the presence of an RAR archive named "!PENTING_LIST OF OFFICERS.rar." This archive contains two files, "Notice to Work-From-Home groups.pdf" and "062023_PENTING_LIST OF SUPERVISORY OFFICERS WHO STILL HAVE NOT REPORT.pdf.exe," which serve as decoys to lure victims into executing the malicious payload.[emaillocker id="1283"]
Upon execution, the large executable "062023_PENTING_LIST OF SUPERVISORY OFFICERS WHO STILL HAVE NOT REPORT.pdf.exe" acts as a dropper, dropping several files, including "Microsoft Office.doc," "IC.exe," "power.exe," and "power.xml." Of note, "IC.exe" is responsible for obtaining the next stage of the infection. The malware also connects to an external server to fetch "seAgnt.exe," which is a renamed copy of a legitimate Microsoft application. However, it is exploited to load the malicious "VCRUNTIME140_1.dll," which is a part of the Microsoft Visual C++ runtime package but used maliciously in this context. The file is heavily obfuscated to obfuscate its true purpose, making analysis challenging. Its primary task seems to be reaching out to an external server to pull down another file, "35g3498734gkb.dat," identical to "VCRUNTIME140_1.dll." Unfortunately, further links in the infection chain were taken down, hindering a deeper analysis of potential final payloads.
Despite the inability to obtain the final payload, MidgeDropper serves as a compelling case study in malware analysis. Its intricate infection chain, code obfuscation, and sideloading techniques make it a noteworthy specimen. Researcher has already put in place multiple protections, including antivirus signatures and web filtering, to shield Fortinet customers from this threat. Additionally, they recommend user awareness training and phishing simulation services to bolster defenses against similar threats. While the mystery of MidgeDropper's ultimate purpose remains unsolved, its existence serves as a reminder of the ever-evolving landscape of cybersecurity threats.
Threat Profile:

References:
The following reports contain further technical details:
https://www.fortinet.com/blog/threat-research/new-midgedropper-variant
[/emaillocker]