국내 방위산업체 공격 동향 보고서
2017-07-03 • Ahnlab • Domestic defense industry attack trend report •
http://download.ahnlab.com/kr/site/library/%5bAnalysis%5dDefense_Industry_Threats.pdf
Attachments
AhnLab examines sustained attacks against South Korean defense contractors and related political, diplomatic, energy, security, and large-enterprise targets from 2010 through 2017. The report separates activity into groups and malware families including Icefog-NG, Red Dot using Escad, Ghost Rifle using Rifdoor and Ghostrat, and Anonymous Phantom using Phandoor, while stating that state sponsorship was not confirmed. Observed infection routes include spearphishing with weaponized or disguised documents, watering-hole sites, and abuse of central management or asset-management systems to distribute malware. Escad infrastructure was spread across many countries, while Rifdoor and Phandoor command-and-control addresses were mostly in South Korea and often used university systems, giving defenders concrete infrastructure patterns to validate alongside malware counts and campaign timelines.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 2f84f7d377ec42f99c38bee8bf1e8cd4 | 2017-07-03 | 2017-07-03 |
| HASH | 1822cb4edb8f40fa9a778e7584e9c44e | 2017-07-03 | 2017-07-03 |
| DOMAIN | hauurri.com | 2017-07-03 | 2017-07-03 |
| DOMAIN | urri.com | 2017-07-03 | 2017-07-03 |
| DOMAIN | news.net | 2017-07-03 | 2017-07-03 |
| DOMAIN | boanews.net | 2017-07-03 | 2017-07-03 |
| DOMAIN | ottct.com | 2017-07-03 | 2017-07-03 |
| DOMAIN | nprottct.com | 2017-07-03 | 2017-07-03 |
| IPv4 | 66.45.231.125 | 2017-07-03 | 2017-07-03 |
| IPv4 | 203.113.122.164 | 2017-07-03 | 2017-07-03 |
| IPv4 | 183.82.97.201 | 2017-07-03 | 2017-07-03 |
| IPv4 | 87.197.125.51 | 2017-07-03 | 2017-07-03 |
| IPv4 | 196.202.33.106 | 2017-07-03 | 2017-07-03 |
| IPv4 | 122.224.214.108 | 2017-07-03 | 2017-07-03 |
| IPv4 | 203.113.122.163 | 2017-07-03 | 2017-07-03 |
| DOMAIN | minihouse.website.iiswan.com | 2013-09-25 | 2017-07-03 |
| DOMAIN | starwings.net | 2013-09-25 | 2017-07-03 |
| DOMAIN | esdlin.com | 2013-09-25 | 2017-07-03 |