고미르 악성코드 분석 보고서

2024-06-27 Nurilab Gomir Malware Analysis Report

https://m.blog.naver.com/nurilab1/223493365290

Thumbnail for 고미르 악성코드 분석 보고서

Nurilab analyzes Gomir, a Linux variant of the GoBear backdoor linked in the source to Kimsuky activity against South Korean organizations and companies. The malware checks for an "install" command-line argument and root privileges, then persists either as a syslogd service or through cron before deleting its original file. Gomir generates a UID from the username and hostname, talks to http://216.189.159.34/mir/index.php with encrypted and Base64-encoded POST data, and can run shell commands, collect host details, change directories, proxy traffic with yamux, and create or exfiltrate files. The report also lists sample hashes that can support clustering and endpoint detection for this Linux backdoor family.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 30584f13c0a9d0c86562c803de35043… 2024-05-16 2024-11-20
HASH 93edc15a20aac8b5193e5b22e35dbb0… 2024-06-27 2024-06-27
HASH e562cf30d17d47347c7e6ffd249fc190 2024-06-27 2024-06-27
IPv4 216.189.159.34 2024-05-16 2024-06-27

Related Actors

Related Reports

2024-07-19 • 60% Match
#Trend #Andariel #Kimsuky #MoonstoneSleet #Lazarus #T1082 #T1059.003 #T1090 #T1140 #T1005 #T1070.004 #T1041 #T1113 #T1555 #T1560 #T1071.001 #T1046 #T1112 #T1115 #T1083 #T1497 #T1056.001 #T1036 #T1027 #T1204.002 #T1566.002 #T1555.003 #T1071 #T1124 #T1222 #T1552 #T1057 #T1583.003 #T1518.001 #T1547.001 #T1053.005 #T1539 #T1608.005 #T1583.001 #T1059.001 #T1053 #T1552.001 #T1566 #T1059 #T1003 #T1497.001 #T1102.001 #T1574.002 #T1562.001 #T1490 #T1486 #T1129 #T1133 #T1571 #T1548 #T1190 #T1203 #T1564.001 #T1087 #T1562.004 #T1218.011 #T1070.006 #T1547 #T1068 #T1614 #T1573 #T1095 #T1562 #T1070 #T1047 #T1056 #T1176 #T1010 #T1033 #T1569.002 #T1543.003 #T1485 #T1012 #T1202 #T1087.002 #T1021.004 #T1222.001 #T1518 #T1564.003 #T1505.003 #T1069.002 #T1564 #T1595.002 #T1027.005 #T1070.001 #T1056.004 #T1584
Shares tag: Kimsuky • Published within a month
« Back