MAR-10288834-2.v1 – North Korean Trojan: TAINTEDSCRIBE

2020-05-12 USCISA

https://www.cisa.gov/news-events/analysis-reports/ar20-133b

Thumbnail for MAR-10288834-2.v1 – North Korean Trojan: TAINTEDSCRIBE

CISA attributes TAINTEDSCRIBE to the North Korean government activity it tracks as HIDDEN COBRA. The Windows implant masquerades as Microsoft Narrator, persists through the user's Startup folder, and connects to 211.192.239.232 over TCP port 8443 using a custom FakeTLS protocol with LFSR-encrypted traffic. It retrieves command modules that support file transfer and execution, command-line access, process control, and system enumeration. CISA published file hashes and detection signatures for the implant and its two EngineDll.dll modules.

Indicators of Compromise

Type Value First Seen Last Seen
YARA CISA_3P_10135536_36_lfsrPolynom… 2020-05-12 2020-05-12
HASH ffca587964d68e3bea67b4add649b06… 2020-05-12 2020-05-12
HASH 19f9a9f7a0c3e6ca72ea88c655b6500… 2020-05-12 2020-05-12
HASH b24f6c60fa4ac76ffc11c2fcee96169… 2020-05-12 2020-05-12
HASH 68fa29a40f64c9594cc3dbe8649f9ebc 2020-05-12 2020-05-12
HASH 77b0b20002ab4a175941a81e309ac67… 2020-05-12 2020-05-12
HASH 2057c0cf4617eab7c91b99975dfb1e2… 2020-05-12 2020-05-12
HASH 0cf64de7a635f5760c4684c18a6ad29… 2020-05-12 2020-05-12
HASH 3005f1308e4519477ac25d7bbf054899 2020-05-12 2020-05-12
HASH b02f86d8261875c9eaf2ee9d491bc7a… 2020-05-12 2020-05-12
HASH 106d915db61436b1a686b86980d4af1… 2020-05-12 2020-05-12
HASH bda6c036fe34dda6aea7797551c7853… 2020-05-12 2020-05-12
HASH 24906e88a757cb535eb17e6c190f371f 2020-05-12 2020-05-12
IPv4 211.192.239.232 2020-05-12 2020-05-12

Related Actors

Related Reports

« Back