疑似 APT37 新攻击武器Fakecheck分析报告

2023-08-25 Knownsec Suspected APT37 new attack weapon Fakecheck analysis report

https://paper.seebug.org/3011/

Thumbnail for 疑似 APT37 新攻击武器Fakecheck分析报告

Knownsec 404 analyzed Korean-language CHM samples themed around insurance, securities, finance, and communications bills and assessed that they targeted South Korea. The CHM chain decompiled itself, dropped and executed a JSE script, downloaded alg.exe, and showed code overlap with AhnLab-disclosed activity while adding numeric string encoding and AhnLab anti-virus checks. The final FakeCheck .NET RAT collects disk, host, browser, bookmark, saved-password, and recent-file data into files under C:\Users\Public\Pictures, uploads the data to C2, and executes server-provided commands. Knownsec notes that some researchers linked the activity to APT37, but says the captured samples and TTPs are not directly tied to its known APT37 intelligence and could represent new APT37 tradecraft or another actor using similar CHM techniques.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 01e7405ddd5545ffb4a57040acc4b6f… 2023-08-25 2023-09-13
HASH a1f6ae788bf3f9ae17893f3b12d557f… 2023-08-25 2023-09-13
HASH 012063e0b7b4f7f3ce50574797112f9… 2023-08-25 2023-09-13
HASH f5e46e18facc6f8fde6658b96dcd379… 2023-08-25 2023-09-13
HASH 578689cb4b06c4d3f1850e4379c4b31… 2023-08-25 2023-09-13
URL https://tosals.ink/uEH5J.html 2023-07-21 2023-08-30
DOMAIN tosals.ink 2023-07-21 2023-08-30
HASH 37feb1d71c6458f71b27dc1ba7cb436… 2023-08-25 2023-08-25
HASH 2b2583019d83e657c219dd6510060f9… 2023-08-25 2023-08-25
URL https://oebil.lat/zyofl 2023-08-25 2023-08-25
URL https://giath.xyz/maiqt 2023-08-25 2023-08-25
URL https://bajut.pro/jdkvr 2023-08-25 2023-08-25
DOMAIN oebil.lat 2023-08-25 2023-08-25
DOMAIN giath.xyz 2023-08-25 2023-08-25
DOMAIN bajut.pro 2023-08-25 2023-08-25
URL https://crilts.cfd/cdeeb 2023-07-20 2023-08-25
DOMAIN crilts.cfd 2023-07-20 2023-08-25

Related Actors

Related Reports

« Back