APT-C-28(ScarCruft)组织对韩国地区攻击活动分析

2023-04-11 • Qihoo360 • APT-C-28 (ScarCruft) analysis of attack activities in South Korea •

https://mp.weixin.qq.com/s/RHbsCLzahLP0zGgC3N5pPQ

Thumbnail for APT-C-28(ScarCruft)组织对韩国地区攻击活动分析

360 Threat Intelligence Center reports that APT-C-28/ScarCruft, also known as Konni, conducted targeted attacks against South Korean entities using Korean-language lure documents related to rewards, payments, cryptocurrency, and contacts. The malicious macro documents downloaded or released CAB payloads, executed batch scripts, selected UAC-bypass methods based on system version and CPU architecture, and installed a disguised Remote Database Service Update service for persistence. The final remote-control DLL collected system and process information, encrypted uploads, and communicated with C2 infrastructure such as 4895750.c1.biz and 5645780.c1.biz. The report ties the activity to Konni based on targeting, lure style, CAB-based loading, remote-control behavior, and overlap with prior payloads used by the group.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9e916c4f58334aafcb033705e7fac6a… 2023-01-30 2024-09-05
DOMAIN 4895750.c1.biz 2022-12-07 2024-09-05
HASH eecb6e8990b825d7ea65320e7370484… 2022-11-16 2024-09-05
HASH bf7a8d81315953cada61abcc34ea924… 2022-11-16 2024-09-05
HASH d3dbd7bb1299096441c5ebba6ce2675e 2023-04-11 2023-04-11
HASH 30a2940974a2e0e7e0aef655240023d… 2023-04-11 2023-04-11
HASH 3f96cd95327a8c801972620c7906dcf… 2023-04-11 2023-04-11
URL http://5645780.c1.biz//index.ph… 2023-04-11 2023-04-11
HASH 5a961d2f53fe1427138f7811d83f8b9… 2023-01-30 2023-04-11
HASH 52df0021852e7286413c6c91cb76b53… 2023-01-30 2023-04-11
HASH a703eebbd981a5ac683099495076228… 2023-01-30 2023-04-11
DOMAIN 5645780.c1.biz 2022-12-07 2023-04-11
DOMAIN c1.biz 2022-11-16 2023-04-11

Related Actors

Related Reports

« Back