PowerWare Ransomware Dropper
CareCERT is aware of a new spam email campaign being used to deliver a malware dropper which is currently delivering a variant of PowerWare Ransomware
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
CareCERT is aware of a new spam email campaign being used to deliver a malware dropper which is currently delivering a variant of PowerWare Ransomware
Affected platforms
The following platforms are known to be affected:
Threat details
Users receive an email inviting them to click on a link to download and view an invoice which requires payment
Example subject lines
- FW: Invoice notification with id number: 880904
- Your invoice notice number: 1112821
- FW: Your payment id number: 28603
Example Malicious URL's
- http[]hypnotherapycenter[.]com/CBHL484280/
- http[]bildnah[.]de/PVXM989517/
- http[]phillstevens[.]co[.]uk/SQFK247917/
The downloaded file is a malicious macro enabled word document which displays a run time error “Run-time error “53” File not found” in an attempt to trick the user into enabling editing and content to allow them to view the content.
If the user enables Marcos, A PowerShell script is invoked which contacts 5 hardcoded malicious URLS and downloads the payload.
The current payload downloaded is a variant of PowerWare Ransomware
Remediation steps
Last edited: 17 January 2022 9:38 am