疑似Group123(APT37)针对中韩外贸人士的攻击活动分析
2019-10-28 • Qihoo360 • Analysis of attacks by suspected Group123 (APT37) targeting foreign trade professionals in China and South Korea •
Tencent Yujian reports a suspected Group123/APT37 phishing campaign observed from late August to mid-September 2019 against people likely connected to China-South Korea trade. The attack used RAR archive lures with Korean-themed filenames and executables disguised as Word documents, then downloaded a disguised JPG from artmuseums.or.kr that decrypted into a RAT installed as svchost.exe. The RAT collected host information and document lists, including Korean HWP files, while an additional module read C2 data from aconfig.ini and dropped a WinRAR command-line component. Tencent assesses the activity as likely Group123 based on the target profile, Korean-language artifacts, Korea-related compromised C2 infrastructure, and similarities to previously reported ScarCruft/Group123 tradecraft, while noting some overlap with Darkhotel-style behavior.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 6f37b758a7a015c2abdab7941b416de… | 2019-10-28 | 2020-03-09 |
| HASH | e26c81c569f6407404a726d48aa4d886 | 2019-10-28 | 2019-10-28 |
| HASH | 8b65bd4c74cd3bbec365ed942a5ccf1… | 2019-10-28 | 2019-10-28 |
| HASH | 558ab3602ad6ec843203dd2e28166be… | 2019-10-28 | 2019-10-28 |
| HASH | 92f8ed8e41d854ba10f287b8b5198a0… | 2019-10-28 | 2019-10-28 |
| HASH | dea0d551900ce032e8684282977bbe5… | 2019-10-28 | 2019-10-28 |
| HASH | 9f8859decf87da412a386141364462f… | 2019-10-28 | 2019-10-28 |
| URL | http://casaabadia.es/ | 2019-10-28 | 2019-10-28 |
| URL | http://artmuseums.or.kr/swfuplo… | 2019-10-28 | 2019-10-28 |
| URL | http://fjtlephare.fr/wp-content… | 2019-10-28 | 2019-10-28 |
| DOMAIN | artmuseums.or.kr | 2019-10-28 | 2019-10-28 |
| DOMAIN | fjtlephare.fr | 2019-10-28 | 2019-10-28 |
| DOMAIN | casaabadia.es | 2019-10-28 | 2019-10-28 |