김수키(Kimsuky) 조직, 실제 주민등록등본 파일로 둔갑한 '블루 에스티메이트 Part3' APT 공격 주의

2020-02-06 • ESTSecurity • Kimsuky organization, beware of ‘Blue Estimate Part3' APT attacks disguised as actual resident registration files •

https://blog.alyac.co.kr/2737

Thumbnail for 김수키(Kimsuky) 조직, 실제 주민등록등본 파일로 둔갑한 '블루 에스티메이트 Part3' APT 공격 주의

ESTsecurity reported a February 2020 Operation Blue Estimate variant that masqueraded as a scanned resident-registration PDF tied to a former education-sector official. The malware used a double-extension SCR executable, displayed a decoy image, and dropped a 64-bit DLL named Hero.dll from embedded resources. The sample reused artifacts seen in earlier Blue Estimate activity, including the HelloSidney mutex, Korean-language build traces, MAC address and serial-number collection code, and an AppleSeed64 PDB path. The excerpt identifies mernberinfo.tech at 213.190.6.159 as C2 infrastructure and states that ESTsecurity believed the activity was linked to Kimsuky.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 6dfce07abc39e5d6aebd74a1850ad65… 2019-12-03 2024-08-14
HASH b4b88ce4be2349612274942f5d5ee93… 2020-02-06 2020-02-06
HASH 4942433b92198ed6f4cf5890fd4a7c5… 2020-02-06 2020-02-06
URL https://www.threatinside.com/ 2020-02-06 2020-02-06
IPv4 213.190.6.159 2020-02-06 2020-02-06
HASH e2487b33a6510d6f51b8aa158a36c6c… 2020-01-23 2020-02-06

Related Actors

Related Reports

« Back