MAR-10288834-3.v1 – North Korean Trojan: PEBBLEDASH
2020-05-12 • USCISA •
CISA, the FBI, and the Department of Defense identified PEBBLEDASH as a full-featured Trojan used by the North Korean government under the HIDDEN COBRA designation. The Windows implant provides file transfer and execution, command-line access, process control, and system-enumeration capabilities. It disguises command-and-control traffic with a simulated TLS handshake and then exchanges RC4-encrypted commands with 112.217.108.138 over port 443. The report supplies file hashes, a YARA rule, and a Snort signature for detection.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 2c879a1d4b6334c59ac5f11c2038d27… | 2020-05-12 | 2020-06-23 |
| HASH | d2de01858417fa3b580b3a95857847d5 | 2020-05-12 | 2020-06-01 |
| IPv4 | 112.217.108.138 | 2020-05-12 | 2020-06-01 |
| YARA | CISA_3P_10135536_02_rc4_key_2 | 2020-05-12 | 2020-05-12 |
| HASH | d620d88dfe1dbc0b407d0c3010ff189… | 2020-05-12 | 2020-05-12 |
| HASH | 220c74af533f4565c4d6f0b4a4ac37c… | 2020-05-12 | 2020-05-12 |
| HASH | aab2868a6ebc6bdee5bd12104191db9… | 2020-05-12 | 2020-05-12 |
Related Actors
Related Reports
Shares tag: HiddenCobra • Same author: USCISA • Published within a week
Shares tag: HiddenCobra • Same author: USCISA • Published within a week
Shares tag: HiddenCobra • Published within a month
Shares tag: HiddenCobra • Same author: USCISA
Shares tag: HiddenCobra • Same author: USCISA
Shares tag: HiddenCobra • Same author: USCISA