SK 커뮤니케이션즈 해킹 관련 상세 분석 보고서
2011-08-04 • Hauri • Detailed analysis report on SK Communications hacking •
Attachments
cfile9.uf136A793E4E3BA0FE059C9E.pdf (507 KB)
The SK Communications breach analysis traces a NateOn-themed malware chain that used `nateon.exe` to install `winsvcfs.dll` as a service-based RAT. The loader modified its own PE header so the binary could operate as a DLL, wrote the result under an All Users path, copied `kernel32.dll` timestamps for camouflage, and launched it through `RUNDLL32.EXE` with the `RqSkce` export. The RAT decrypted its strings and C2 settings at runtime, attempted port-80 communication with `nateon.duamlive.com` after checking `download.windowsupdate.com`, and registered persistence through `svchost.exe -k LocalService` service keys. Its command set covered database queries, registry manipulation, network and socket operations, service control, file operations, screenshots, process/module enumeration, command execution, and system power/session actions, supporting the report’s description of malware used in the breach that exposed about 35 million Nate user records.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 74455d5e8f99272aec64bce106b1e8f… | 2011-08-04 | 2011-09-24 |
| HASH | 727c5a2c3db079351a79367a1d9eada… | 2011-08-04 | 2011-08-04 |