국내 보안업체의 유효한 디지털서명을 탑재한 악성코드 주의!
2019-07-30 • ESTSecurity • Beware of malware containing a valid digital signature from a domestic security company! •
ESRC warned that malware was distributed with a valid digital signature from a Korean DRM and document-security vendor, increasing the chance of bypassing trust-based defenses. After infection, the malware registered itself in Task Scheduler as “Jav Maintenance64” for recurring execution and enabled the attacker to run additional actions on the host. The analysis linked the custom encryption logic to earlier APT activity against Korean public and financial institutions and assessed the signed payload and malicious URL as part of an early-stage campaign. Defenders should review signed-code trust decisions, scheduled-task persistence, and the listed hashes and URLs from the report.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 9758efcf96343d0ef83854860195c4b4 | 2019-07-30 | 2021-06-15 |
| IPv4 | 51.254.60.208 | 2019-07-30 | 2020-04-16 |
| HASH | 8ba860e1340b29439ff5f6e3df98d537 | 2019-07-30 | 2019-07-30 |
| HASH | e6037a8487b85118532184d397a6eedd | 2019-07-30 | 2019-07-30 |
| HASH | f1af683eba25bb9cdf4fa88176fc6128 | 2019-07-30 | 2019-07-30 |