최신 APT 캠페인, 작전명 유령 꼭두각시(Operation Ghost Puppet)
2018-09-24 • ESTSecurity • Latest APT campaign, Operation Ghost Puppet •
ESRC analyzed Operation Ghost Puppet, an August 2018 campaign using a malicious HWP document titled as a notice about illegal fund-raising activity. The document embedded compressed PostScript under HWP BinData and abused GhostScript processing to decode shellcode, inject into explorer.exe, and download gcoin2.swf from tpddata.com. The payload provided remote-control functionality and contacted C2 paths on pakteb.com, nuokejs.com, and qdbazaar.com. The source highlights targeting logic around Korean HWP documents, which are commonly used in South Korean public-sector environments, and compares metadata, XOR decoding structures, and command strings with earlier Korean intrusion cases.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 3ff4ebae6c255d4ae6b747a77f2821f… | 2018-06-22 | 2020-05-12 |
| HASH | 4c2efe2f1253b94f16a1cab032f36c7… | 2014-12-04 | 2020-03-09 |
| HASH | 0060119ae5803a7fbdc8f246d8955ac… | 2018-09-24 | 2018-09-24 |
| HASH | 4a9429b35daa56d58988c300f8be639… | 2018-09-24 | 2018-09-24 |
| HASH | f416f695895f37b598a487cf247295d… | 2018-09-24 | 2018-09-24 |
| DOMAIN | bizforms.co.kr | 2018-09-24 | 2018-09-24 |
| IPv4 | 104.221.134.28 | 2018-09-24 | 2018-09-24 |
| IPv4 | 104.195.1.39 | 2018-09-24 | 2018-09-24 |
| IPv4 | 104.31.74.89 | 2018-09-24 | 2018-09-24 |
| URL | https://tpddata.com/flash/gcoin… | 2018-06-22 | 2018-09-24 |
| URL | https://tpddata.com/flash/gcoin… | 2018-06-22 | 2018-09-24 |
| DOMAIN | tpddata.com | 2018-06-22 | 2018-09-24 |
| HASH | 5831e614d79f3259fd48cfd5cd3c7e8… | 2017-05-22 | 2018-09-24 |
| HASH | 0cb8ec97795066ecf77d92a5dbce7d3… | 2017-05-12 | 2018-09-24 |