MAR-10288834-3.v1 – North Korean Trojan: PEBBLEDASH

2020-05-12 • USCISA •

https://www.cisa.gov/news-events/analysis-reports/ar20-133c

Thumbnail for MAR-10288834-3.v1 – North Korean Trojan: PEBBLEDASH

CISA, the FBI, and the Department of Defense identified PEBBLEDASH as a full-featured Trojan used by the North Korean government under the HIDDEN COBRA designation. The Windows implant provides file transfer and execution, command-line access, process control, and system-enumeration capabilities. It disguises command-and-control traffic with a simulated TLS handshake and then exchanges RC4-encrypted commands with 112.217.108.138 over port 443. The report supplies file hashes, a YARA rule, and a Snort signature for detection.

Indicators of Compromise

Type Value First Seen Last Seen
HASH aab2868a6ebc6bdee5bd12104191db9… 2020-05-12 2020-06-23
IPv4 112.217.108.138 2020-05-12 2020-06-01
YARA CISA_3P_10135536_02_rc4_key_2 2020-05-12 2020-05-12
HASH d620d88dfe1dbc0b407d0c3010ff189… 2020-05-12 2020-05-12

Related Actors

Related Reports

« Back