PC방에서 플레이되는 고포류 게임을 노리는 악성코드 정보

2018-09-14 • hummingbird • Malware information targeting high-definition games played in PC rooms •

https://hummingbird.tistory.com/6707

Thumbnail for PC방에서 플레이되는 고포류 게임을 노리는 악성코드 정보

A Korean malware operation targeted public PC-room environments where users played go-stop, poker, Baduki, Matgo, Vanilla Game, and related online gambling/card games for financial gain. The installer or updater dropped syswnt.exe, cleaned prior components and the SQLSVC service, then contacted a shortened URL that led to a Japan-hosted server used to download sqlservice.exe and GInsert.exe. sqlservice.exe installed itself as the SQLSVC service under Common Files\Services, created additional Windows modules, and launched or injected activity through Windows Sidebar to hide execution and resist termination. GInsert.exe appeared designed to interfere with Ghost recovery images, while other modules checked PC-room management software and disabled recovery tools such as Shadow Defender and Norton Ghost to improve persistence. The malware’s apparent purpose was to join targeted game rooms, inspect opponents’ cards, and improve win rates to acquire in-game money.

Indicators of Compromise

Type Value First Seen Last Seen
HASH c71f604973ca09e9c15249c0c163c67… 2018-09-14 2018-09-14
HASH 42ab3542543812bb403d6c95d7f91c7… 2018-09-14 2018-09-14
HASH 52bbec23f8687ffb85ed4f85a801635… 2018-09-14 2018-09-14
HASH e8ade2580be93921b51ff889130c346… 2018-09-14 2018-09-14
HASH 805c57b9ef3590c4c85f0086f6fbb72… 2018-09-14 2018-09-14
HASH 73df5ec3d3ce0a18a570cbe1c340a3b… 2018-09-14 2018-09-14
HASH f9897914358ab5a284a41ac08fc0d04… 2018-09-14 2018-09-14
HASH 980bbb8f01cd0935c934cd9401b0a72… 2018-09-14 2018-09-14
« Back