疑似 APT37 新攻击武器Fakecheck分析报告
2023-08-25 • Knownsec • Suspected APT37 new attack weapon Fakecheck analysis report •
Knownsec 404 analyzed Korean-language CHM samples themed around insurance, securities, finance, and communications bills and assessed that they targeted South Korea. The CHM chain decompiled itself, dropped and executed a JSE script, downloaded alg.exe, and showed code overlap with AhnLab-disclosed activity while adding numeric string encoding and AhnLab anti-virus checks. The final FakeCheck .NET RAT collects disk, host, browser, bookmark, saved-password, and recent-file data into files under C:\Users\Public\Pictures, uploads the data to C2, and executes server-provided commands. Knownsec notes that some researchers linked the activity to APT37, but says the captured samples and TTPs are not directly tied to its known APT37 intelligence and could represent new APT37 tradecraft or another actor using similar CHM techniques.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 01e7405ddd5545ffb4a57040acc4b6f… | 2023-08-25 | 2023-09-13 |
| HASH | a1f6ae788bf3f9ae17893f3b12d557f… | 2023-08-25 | 2023-09-13 |
| HASH | 012063e0b7b4f7f3ce50574797112f9… | 2023-08-25 | 2023-09-13 |
| HASH | f5e46e18facc6f8fde6658b96dcd379… | 2023-08-25 | 2023-09-13 |
| HASH | 578689cb4b06c4d3f1850e4379c4b31… | 2023-08-25 | 2023-09-13 |
| URL | https://tosals.ink/uEH5J.html | 2023-07-21 | 2023-08-30 |
| DOMAIN | tosals.ink | 2023-07-21 | 2023-08-30 |
| HASH | 37feb1d71c6458f71b27dc1ba7cb436… | 2023-08-25 | 2023-08-25 |
| HASH | 2b2583019d83e657c219dd6510060f9… | 2023-08-25 | 2023-08-25 |
| URL | https://oebil.lat/zyofl | 2023-08-25 | 2023-08-25 |
| URL | https://giath.xyz/maiqt | 2023-08-25 | 2023-08-25 |
| URL | https://bajut.pro/jdkvr | 2023-08-25 | 2023-08-25 |
| DOMAIN | oebil.lat | 2023-08-25 | 2023-08-25 |
| DOMAIN | giath.xyz | 2023-08-25 | 2023-08-25 |
| DOMAIN | bajut.pro | 2023-08-25 | 2023-08-25 |
| URL | https://crilts.cfd/cdeeb | 2023-07-20 | 2023-08-25 |
| DOMAIN | crilts.cfd | 2023-07-20 | 2023-08-25 |