국내 IP에서 유포된 PureCrypter 적용 Formbook 페이로드 분석

2025-08-29 ENKI Analysis of a FormBook Payload Loaded by PureCrypter and Distributed from a South Korean IP Address

https://www.enki.co.kr/media-center/blog/analysis-of-formbook-payload-loaded-by-purecrypter-distributed-from-south-korean-ip

Thumbnail for 국내 IP에서 유포된 PureCrypter 적용 Formbook 페이로드 분석

A phishing email sent to a South Korean energy-company domain delivered a RAR attachment containing a .NET executable disguised as an air cargo waybill. The executable was identified as a PureCrypter first-stage loader that contacted 158.247.250[.]251 for encrypted content, decrypted it with AES values, and loaded the next .NET stage in memory. The analyzed PureCrypter configuration supported persistence, anti-debugging, sandbox and VM checks, AMSI and ETW patching, Windows Defender exclusions, self-copying to %AppData%\temp.exe, and multiple injection modes. Its final payload was Formbook, injected through process hollowing with explorer.exe used for parent-process spoofing, while the Formbook analysis described dynamic API use, layered function decryption, anti-debugging, and Heaven's Gate behavior. The source notes that the C2 server showed similarities to other Kimsuky attack infrastructure, but the technical body centers on the PureCrypter-to-Formbook delivery chain and the South Korea-linked phishing lure.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 158.247.240.40 2025-08-29 2026-04-17
HASH 6e5198c3aae9005cc58d011a8c6f0bec 2025-08-29 2025-08-29
HASH 42d24ccfb0a05c5f299181ca3afc7ae3 2025-08-29 2025-08-29
HASH ca9cb7bb06398670abc6d19186c336cd 2025-08-29 2025-08-29
HASH 310ebb7ca19ff9b75d4054c340b0c82e 2025-08-29 2025-08-29
HASH 52a321e48902b8fbd1e984d9bd15f278 2025-08-29 2025-08-29
HASH 108b5fd1b62489fd5cdb4ebd4a463226 2025-08-29 2025-08-29
HASH 3a665cf99a9b7a79f4fecb77bbe2bf5… 2025-08-29 2025-08-29
HASH 81bfe3b3204ede1fca418e44aa19b310 2025-08-29 2025-08-29
HASH f96cf8cafbaf112548f6f122d9270cca 2025-08-29 2025-08-29
HASH a872738399912091389ae9720d5e068… 2025-08-29 2025-08-29
HASH a6c26a0b5df0db6a35b15c24342f27f8 2025-08-29 2025-08-29
HASH 1dc0668a628ea91766a75c87319a23b… 2025-08-29 2025-08-29
HASH e78be07019dfaf682c601985ac3ba424 2025-08-29 2025-08-29
IPv4 147.135.109.226 2025-08-29 2025-08-29
IPv4 95.214.54.164 2025-08-29 2025-08-29
IPv4 195.177.94.43 2025-08-29 2025-08-29
IPv4 158.247.250.251 2025-08-29 2025-08-29
IPv4 161.248.239.119 2025-08-29 2025-08-29
DOMAIN dhl.com 2023-09-26 2025-08-29

Related Actors

Related Reports

2025-08-25 • 43% Match
#Lazarus #GolangGhost #T1059.003 #T1140 #T1005 #T1070.004 #T1041 #T1113 #T1071.001 #T1115 #T1083 #T1056.001 #T1204.002 #T1566.002 #T1555.003 #T1057 #T1059.005 #T1518.001 #T1566.001 #T1547.001 #T1059.001 #T1497.001 #T1219 #T1574.002 #T1562.001 #T1622 #T1027.002 #T1573.001 #T1190 #T1123 #T1132.002 #T1564.001 #T1548.002 #T1055.012 #T1027.007 #T1217 #T1106 #T1027.009 #T1036.003 #T1055.002 #T1036.007 #T1059.010 #T1136.001 #T1134.004 #T1614.001 #T1574.007 #T1098.007 #T1010 #T1071.004 #T1021.002 #T1021.006
Shares tags: T1059.003, T1140, T1005 • Published within a week
« Back