Skip to content

Emerging Threats

Ursnif Malware โ€” Italian Tax Agency lure

ยท frtg ยท 2 min read

Between 8 and 21 March 2021 we identified a malicious email campaign distributing the Ursnif malware.

Ursnif malware is classified as a “๐‘ฉ๐’‚๐’๐’Œ๐’Š๐’๐’ˆ ๐‘ป๐’“๐’๐’‹๐’‚๐’”, primarily associated with user data compromise and frequently deployed as an initial vector for more complex infrastructure breaches and Ransomware attacks.

The email subject line mimics the Italian Revenue Agency (Agenzia delle Entrate), with a malicious Excel file “.xlsb” attached to the message.

Figure 1 – Example of malicious email

The dropper

Upon opening the ๐—˜๐˜…๐—ฐ๐—ฒ๐—น document and enabling Macros, a sequence of actions is initiated that includes downloading and executing the second stage of the malware (a “.dll” ๐’‡๐’Š๐’๐’†).

Figure 2 – Malicious Excel

Malware Behavior

The dropper downloads the dll ๐’‡๐’Š๐’๐’† from the domain satisonline[.]bar (62[.]173[.]147[.]107), retrieving the file “signup.jpg”. This activity is consistent with Cyber Threat Intelligence observations of Ursnif distribution infrastructure.

Figure 3 – Network communication excerpt

The ๐’‡๐’Š๐’๐’† is saved to a randomized directory path of the form: “C:\zVAJUlB\WPTqlPR\RjuoPEa.dll”

At this stage the endpoint is compromised, with initial connections established to “๐—–๐—ผ๐—บ๐—บ๐—ฎ๐—ป๐—ฑ ๐—ฎ๐—ป๐—ฑ ๐—–๐—ผ๐—ป๐˜๐—ฟ๐—ผ๐—น” servers for remote system access (T1071 – Application Layer Protocol, T1090 – Proxy).

Ursnif campaigns leveraging macro-enabled Office documents remain a persistent delivery mechanism for banking trojans. Organizations must enforce application whitelisting, disable macro execution by default, and maintain network-based detection signatures for known command-and-control infrastructure to mitigate this threat vector.

Speak with our analysts Blog home