lazarusholic

Everyday is lazarus.dayβ

Analyzing the North Korean hacking group APT37 (Scarcruft) attack with CVE-2024-38178 : Operation Code On Toast

2024-10-23, Igloo
https://www.igloopedia.com/128f216a-760c-81d3-99d1-c5918596ab01
#APT37 #CVE-2024-38178 #CodeonToast

IoC

https://cloud-api.yandex.net/v1/disk/resources/download?path=%s
http://img.mobonad.com/images/20230912/43
https://api.onedrive.com/v1.0/shares/u!aHR0cHM6Ly8xZHJ2Lm1zL3UvcyFBajh0Ynp6N19QRk5seTZBa1hrTzB0cVRQLTltP2U9d1FpQ2Xn/root/content
https://1drv.ms/u/s!Aj8tbzz7_PFNly6AkXkO0tqTP-9m?e=wQiCe
http://www.goOOOOO.net/images/top_08.bak
https://cloud-api.yandex.net/v1/disk/resources/upload?path=%s&overwrite=%s
https://api.onedrive.com/v1.0/shares/u!aHR0cHM6Ly8xZHJ2Lm1zL3UvcyFBajh0Ynp6N19QRk5seTZBa1hrTzB0cVRQLTItP2U9d1FpQ2xn/root/content
http://www.dramaskin.co.kr/images/main/ban04.bak
https://1drv.ms/u/s!Aj8tbzz7_PFNly6AkXkO0tqTP-2-?e=wQiClg
http://www.mobonad.com
https://cloud-api.yandex.net/v1/disk/resources?path=%s&limit=50
https://cloud-api.yandex.net/v1/disk/resources?path=%s&permanently=%s
37.9.68.0
87.250.241.0
222.97.189.148
141.8.156.0
84.32.131.214
141.8.157.0
213.180.204.127
b18a8ea838b6760f4857843cafe5717d
63ce7af76ecdc200f3cbf5739368b126
24eef6e96fb9b37ea30858af142efd50
a389cb235c9d266ad65d01d16c89118d
bb31defd97a4acedbab7fc18e2b0f82b
e85e1328c08f52594418b5fca381f7c6
da2a5353400bd5f47178cd7dae7879c5
68c191b310be1c1dea5210504a14500b
56cc7a9ba1c267f30e88652cddd8832f
d72d2b96729ed2cbdb27b9459c25e6d8
c1dbc87e91fe377b08069d079b76a2ee
b9d4702c1b72659f486259520f48b483
edcef6641d24bedd53a1e45547c8beba
d4219bc120730396ce03cbc23c2c7edb
bd2d599ab51f9068d8c8eccadaca103d
742dff1c2d750c63f04ede4ea3765c5f
7f89a559f7fc716b9ae8b56b65cfc758
b672c263914d4e70b7989dd9fe8ecacd
e9c7901e6ecf75b630e00b2389c1bbcc
e11bb2478930d0b5f6c473464f2a2B6e
9bbfe7ce1f6229970cdbeeb804342a4d
dab4f366af50410467e6184e87082952