고미르 악성코드 분석 보고서
2024-06-27 • Nurilab • Gomir Malware Analysis Report •
Nurilab analyzes Gomir, a Linux variant of the GoBear backdoor linked in the source to Kimsuky activity against South Korean organizations and companies. The malware checks for an "install" command-line argument and root privileges, then persists either as a syslogd service or through cron before deleting its original file. Gomir generates a UID from the username and hostname, talks to http://216.189.159.34/mir/index.php with encrypted and Base64-encoded POST data, and can run shell commands, collect host details, change directories, proxy traffic with yamux, and create or exfiltrate files. The report also lists sample hashes that can support clustering and endpoint detection for this Linux backdoor family.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 30584f13c0a9d0c86562c803de35043… | 2024-05-16 | 2024-11-20 |
| HASH | 93edc15a20aac8b5193e5b22e35dbb0… | 2024-06-27 | 2024-06-27 |
| HASH | e562cf30d17d47347c7e6ffd249fc190 | 2024-06-27 | 2024-06-27 |
| IPv4 | 216.189.159.34 | 2024-05-16 | 2024-06-27 |