Targeted Attacks Against South Korean Entities May Have Been as Early as November 2017

2018-02-02 • Flashpoint-intel •

https://www.flashpoint-intel.com/blog/targeted-attacks-south-korean-entities/

Thumbnail for Targeted Attacks Against South Korean Entities May Have Been as Early as November 2017

Flashpoint reported that KrCERT warned on January 31, 2018 about Adobe Flash CVE-2018-4878 affecting Flash Player ActiveX 28.0.0.137 and earlier. A South Korean researcher said the exploit was being used against South Korean entities in a Korean cosmetics-themed Excel document and claimed North Korean actor involvement, but Flashpoint noted that the claim was not independently corroborated. Debug metadata suggested exploitation may have started as early as November 14, 2017, with the builder path F:\work\flash\obfuscation\loadswf\src. The archive also preserves detection material, including MD5s, two C2 URLs under Korean domains, and a YARA rule for Office-embedded Flash payloads.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 28.0.0.137 2018-02-02 2018-03-14
YARA crime_ole_loadswf_cve_2018_4878 2018-02-02 2018-02-02
HASH 3004196da6055c6f062c94a9aae8dc3… 2018-02-02 2018-02-02
HASH 7ac5d30bec28b2e139a3333286eea52… 2018-02-02 2018-02-02
HASH 14c58e3894258c54e12d52d0fba0aaf… 2018-02-02 2018-02-02
HASH 1a3269253784f76e3480e4b3de312df… 2018-02-02 2018-02-02
URL http://www.1588-2040.co.kr/desi… 2018-02-02 2018-02-02
URL http://www.dylboiler.co.kr/admi… 2018-02-02 2018-02-02

Related Reports

« Back