금융권을 타깃으로 한 I사 위장 악성코드
2016-02-24 • Hauri • Company I disguised malware targeting the financial sector •
http://www.hauri.co.kr/security/issue_view.html?intSeq=279&page=6&article_num=220
The excerpt analyzes a backdoor that receives command codes from a C&C server and can download and execute additional malware, run CMD commands, and control the infected PC. It persists by copying itself into a specific folder, generating a random service name based on existing svchost.exe-backed services, registering itself as a service, and deleting the original loader artifacts. The malware tampers with file creation time through Kernel32.dll, attempts C&C communication when running as a service, and encrypts stolen host details before transmission. Reported collection includes the login account, operating system version, IP address, and current system time, giving defenders concrete behaviors for service-creation, persistence, and command-and-control detection.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 192.99.223.115 | 2016-02-23 | 2020-04-16 |
| IPv4 | 165.194.123.67 | 2016-02-23 | 2020-04-16 |