국내 방위산업체 공격 동향 보고서

2017-07-03 Ahnlab Domestic defense industry attack trend report

http://download.ahnlab.com/kr/site/library/%5bAnalysis%5dDefense_Industry_Threats.pdf

Attachments

5bAnalysis5dDefense_Industry_Threats.pdf (1 MB)

Thumbnail for 국내 방위산업체 공격 동향 보고서

AhnLab examines sustained attacks against South Korean defense contractors and related political, diplomatic, energy, security, and large-enterprise targets from 2010 through 2017. The report separates activity into groups and malware families including Icefog-NG, Red Dot using Escad, Ghost Rifle using Rifdoor and Ghostrat, and Anonymous Phantom using Phandoor, while stating that state sponsorship was not confirmed. Observed infection routes include spearphishing with weaponized or disguised documents, watering-hole sites, and abuse of central management or asset-management systems to distribute malware. Escad infrastructure was spread across many countries, while Rifdoor and Phandoor command-and-control addresses were mostly in South Korea and often used university systems, giving defenders concrete infrastructure patterns to validate alongside malware counts and campaign timelines.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 2f84f7d377ec42f99c38bee8bf1e8cd4 2017-07-03 2017-07-03
HASH 1822cb4edb8f40fa9a778e7584e9c44e 2017-07-03 2017-07-03
DOMAIN hauurri.com 2017-07-03 2017-07-03
DOMAIN urri.com 2017-07-03 2017-07-03
DOMAIN news.net 2017-07-03 2017-07-03
DOMAIN boanews.net 2017-07-03 2017-07-03
DOMAIN ottct.com 2017-07-03 2017-07-03
DOMAIN nprottct.com 2017-07-03 2017-07-03
IPv4 66.45.231.125 2017-07-03 2017-07-03
IPv4 203.113.122.164 2017-07-03 2017-07-03
IPv4 183.82.97.201 2017-07-03 2017-07-03
IPv4 87.197.125.51 2017-07-03 2017-07-03
IPv4 196.202.33.106 2017-07-03 2017-07-03
IPv4 122.224.214.108 2017-07-03 2017-07-03
IPv4 203.113.122.163 2017-07-03 2017-07-03
DOMAIN minihouse.website.iiswan.com 2013-09-25 2017-07-03
DOMAIN starwings.net 2013-09-25 2017-07-03
DOMAIN esdlin.com 2013-09-25 2017-07-03

Related Actors

Related Reports

« Back