국내 보안업체의 유효한 디지털서명을 탑재한 악성코드 주의!

2019-07-30 • ESTSecurity • Beware of malware containing a valid digital signature from a domestic security company! •

https://blog.alyac.co.kr/2446

Thumbnail for 국내 보안업체의 유효한 디지털서명을 탑재한 악성코드 주의!

ESRC warned that malware was distributed with a valid digital signature from a Korean DRM and document-security vendor, increasing the chance of bypassing trust-based defenses. After infection, the malware registered itself in Task Scheduler as “Jav Maintenance64” for recurring execution and enabled the attacker to run additional actions on the host. The analysis linked the custom encryption logic to earlier APT activity against Korean public and financial institutions and assessed the signed payload and malicious URL as part of an early-stage campaign. Defenders should review signed-code trust decisions, scheduled-task persistence, and the listed hashes and URLs from the report.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 315c06bd8c75f99722fd014b4fb4bd8… 2019-07-30 2021-06-15
IPv4 51.254.60.208 2019-07-30 2020-04-16
HASH f895757608b7725674628d731ec9fe9… 2019-07-30 2020-03-09
HASH 35c757abdee4810f647436cef245e51… 2019-07-30 2019-07-30
HASH 99b77d8b77531624aed40439ba23347… 2019-07-30 2019-07-30

Related Reports

« Back