국내 보안업체의 유효한 디지털서명을 탑재한 악성코드 주의!

2019-07-30 ESTSecurity Beware of malware containing a valid digital signature from a domestic security company!

https://blog.alyac.co.kr/2446

Thumbnail for 국내 보안업체의 유효한 디지털서명을 탑재한 악성코드 주의!

ESRC warned that malware was distributed with a valid digital signature from a Korean DRM and document-security vendor, increasing the chance of bypassing trust-based defenses. After infection, the malware registered itself in Task Scheduler as “Jav Maintenance64” for recurring execution and enabled the attacker to run additional actions on the host. The analysis linked the custom encryption logic to earlier APT activity against Korean public and financial institutions and assessed the signed payload and malicious URL as part of an early-stage campaign. Defenders should review signed-code trust decisions, scheduled-task persistence, and the listed hashes and URLs from the report.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9758efcf96343d0ef83854860195c4b4 2019-07-30 2021-06-15
IPv4 51.254.60.208 2019-07-30 2020-04-16
HASH 8ba860e1340b29439ff5f6e3df98d537 2019-07-30 2019-07-30
HASH e6037a8487b85118532184d397a6eedd 2019-07-30 2019-07-30
HASH f1af683eba25bb9cdf4fa88176fc6128 2019-07-30 2019-07-30

Related Reports

« Back