악성코드 분석 보고서 [3.20 변종 악성코드]

2014-07-17 NSHC Malware Analysis Report [3.20 Variant Malware]

https://www.dailysecu.com/bbs/download.php?table=bbs_10&savefilename=bbs_10_1295_3090.pdf&filename=3.20%20%EB%B3%80%EC%A2%85%20%EC%95%85%EC%84%B1%EC%BD%94%EB%93%9C%20%EB%B6%84%EC%84%9D-Red%20Alert.pdf

Attachments

3.20_변종_악성코드_분석-Red_alert.pdf (930 KB)

Thumbnail for 악성코드 분석 보고서 [3.20 변종 악성코드]

NSHC analyzed a July 2014 backdoor distributed through Korean ActiveX flaws and CVE-2014-0515 in Flash Player, describing it as a variant related to the March 20 attacks and suspected North Korean activity. The MFC dropper allocates code in memory, checks VMware, VirtualBox, and sandbox artifacts, and exits and deletes itself when V3Lite is running. Once installed, it collects the OS version, computer name, and MAC address, sends them to a masked C2 server, waits for commands, and can download second-stage payloads. The report supplies three MD5 hashes and one SHA-256 value; its distribution and C2 URLs are partially masked.

Indicators of Compromise

Type Value First Seen Last Seen
HASH cbb84a85f8c2503cf5885f9156e8f5c… 2014-07-17 2017-07-27
HASH a3d5f7afe72489b58ad8609bc422368… 2014-07-17 2017-07-27
HASH AB1F2AA208FE70678CA1EE17DDC8E7EC 2014-07-17 2014-07-17

Related Reports

« Back