국내 IP에서 유포된 PureCrypter 적용 Formbook 페이로드 분석
2025-08-29 • ENKI • Analysis of a FormBook Payload Loaded by PureCrypter and Distributed from a South Korean IP Address •
A phishing email sent to a South Korean energy-company domain delivered a RAR attachment containing a .NET executable disguised as an air cargo waybill. The executable was identified as a PureCrypter first-stage loader that contacted 158.247.250[.]251 for encrypted content, decrypted it with AES values, and loaded the next .NET stage in memory. The analyzed PureCrypter configuration supported persistence, anti-debugging, sandbox and VM checks, AMSI and ETW patching, Windows Defender exclusions, self-copying to %AppData%\temp.exe, and multiple injection modes. Its final payload was Formbook, injected through process hollowing with explorer.exe used for parent-process spoofing, while the Formbook analysis described dynamic API use, layered function decryption, anti-debugging, and Heaven's Gate behavior. The source notes that the C2 server showed similarities to other Kimsuky attack infrastructure, but the technical body centers on the PureCrypter-to-Formbook delivery chain and the South Korea-linked phishing lure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 158.247.240.40 | 2025-08-29 | 2026-04-17 |
| HASH | 6e5198c3aae9005cc58d011a8c6f0bec | 2025-08-29 | 2025-08-29 |
| HASH | 42d24ccfb0a05c5f299181ca3afc7ae3 | 2025-08-29 | 2025-08-29 |
| HASH | ca9cb7bb06398670abc6d19186c336cd | 2025-08-29 | 2025-08-29 |
| HASH | 310ebb7ca19ff9b75d4054c340b0c82e | 2025-08-29 | 2025-08-29 |
| HASH | 52a321e48902b8fbd1e984d9bd15f278 | 2025-08-29 | 2025-08-29 |
| HASH | 108b5fd1b62489fd5cdb4ebd4a463226 | 2025-08-29 | 2025-08-29 |
| HASH | 3a665cf99a9b7a79f4fecb77bbe2bf5… | 2025-08-29 | 2025-08-29 |
| HASH | 81bfe3b3204ede1fca418e44aa19b310 | 2025-08-29 | 2025-08-29 |
| HASH | f96cf8cafbaf112548f6f122d9270cca | 2025-08-29 | 2025-08-29 |
| HASH | a872738399912091389ae9720d5e068… | 2025-08-29 | 2025-08-29 |
| HASH | a6c26a0b5df0db6a35b15c24342f27f8 | 2025-08-29 | 2025-08-29 |
| HASH | 1dc0668a628ea91766a75c87319a23b… | 2025-08-29 | 2025-08-29 |
| HASH | e78be07019dfaf682c601985ac3ba424 | 2025-08-29 | 2025-08-29 |
| IPv4 | 147.135.109.226 | 2025-08-29 | 2025-08-29 |
| IPv4 | 95.214.54.164 | 2025-08-29 | 2025-08-29 |
| IPv4 | 195.177.94.43 | 2025-08-29 | 2025-08-29 |
| IPv4 | 158.247.250.251 | 2025-08-29 | 2025-08-29 |
| IPv4 | 161.248.239.119 | 2025-08-29 | 2025-08-29 |
| DOMAIN | dhl.com | 2023-09-26 | 2025-08-29 |