악성코드 분석 보고서 [3.20 변종 악성코드]
2014-07-17 • NSHC • Malware Analysis Report [3.20 Variant Malware] •
Attachments
NSHC analyzed a July 2014 backdoor distributed through Korean ActiveX flaws and CVE-2014-0515 in Flash Player, describing it as a variant related to the March 20 attacks and suspected North Korean activity. The MFC dropper allocates code in memory, checks VMware, VirtualBox, and sandbox artifacts, and exits and deletes itself when V3Lite is running. Once installed, it collects the OS version, computer name, and MAC address, sends them to a masked C2 server, waits for commands, and can download second-stage payloads. The report supplies three MD5 hashes and one SHA-256 value; its distribution and C2 URLs are partially masked.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | cbb84a85f8c2503cf5885f9156e8f5c… | 2014-07-17 | 2017-07-27 |
| HASH | a3d5f7afe72489b58ad8609bc422368… | 2014-07-17 | 2017-07-27 |
| HASH | AB1F2AA208FE70678CA1EE17DDC8E7EC | 2014-07-17 | 2014-07-17 |