MAR-10288834-2.v1 – North Korean Trojan: TAINTEDSCRIBE

2020-05-12 • USCISA •

https://www.cisa.gov/news-events/analysis-reports/ar20-133b

Thumbnail for MAR-10288834-2.v1 – North Korean Trojan: TAINTEDSCRIBE

CISA attributes TAINTEDSCRIBE to the North Korean government activity it tracks as HIDDEN COBRA. The Windows implant masquerades as Microsoft Narrator, persists through the user's Startup folder, and connects to 211.192.239.232 over TCP port 8443 using a custom FakeTLS protocol with LFSR-encrypted traffic. It retrieves command modules that support file transfer and execution, command-line access, process control, and system enumeration. CISA published file hashes and detection signatures for the implant and its two EngineDll.dll modules.

Indicators of Compromise

Type Value First Seen Last Seen
YARA CISA_3P_10135536_36_lfsrPolynom… 2020-05-12 2020-05-12
HASH 19f9a9f7a0c3e6ca72ea88c655b6500… 2020-05-12 2020-05-12
HASH 2057c0cf4617eab7c91b99975dfb1e2… 2020-05-12 2020-05-12
HASH 106d915db61436b1a686b86980d4af1… 2020-05-12 2020-05-12
IPv4 211.192.239.232 2020-05-12 2020-05-12

Related Actors

Related Reports

« Back