MAR-10288834-3.v1 – North Korean Trojan: PEBBLEDASH

2020-05-12 USCISA

https://www.cisa.gov/news-events/analysis-reports/ar20-133c

Thumbnail for MAR-10288834-3.v1 – North Korean Trojan: PEBBLEDASH

CISA, the FBI, and the Department of Defense identified PEBBLEDASH as a full-featured Trojan used by the North Korean government under the HIDDEN COBRA designation. The Windows implant provides file transfer and execution, command-line access, process control, and system-enumeration capabilities. It disguises command-and-control traffic with a simulated TLS handshake and then exchanges RC4-encrypted commands with 112.217.108.138 over port 443. The report supplies file hashes, a YARA rule, and a Snort signature for detection.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 2c879a1d4b6334c59ac5f11c2038d27… 2020-05-12 2020-06-23
HASH d2de01858417fa3b580b3a95857847d5 2020-05-12 2020-06-01
IPv4 112.217.108.138 2020-05-12 2020-06-01
YARA CISA_3P_10135536_02_rc4_key_2 2020-05-12 2020-05-12
HASH d620d88dfe1dbc0b407d0c3010ff189… 2020-05-12 2020-05-12
HASH 220c74af533f4565c4d6f0b4a4ac37c… 2020-05-12 2020-05-12
HASH aab2868a6ebc6bdee5bd12104191db9… 2020-05-12 2020-05-12

Related Actors

Related Reports

« Back