금융권을 타깃으로 한 I사 위장 악성코드

2016-02-24 Hauri Company I disguised malware targeting the financial sector

http://www.hauri.co.kr/security/issue_view.html?intSeq=279&page=6&article_num=220

Thumbnail for 금융권을 타깃으로 한 I사 위장 악성코드

The excerpt analyzes a backdoor that receives command codes from a C&C server and can download and execute additional malware, run CMD commands, and control the infected PC. It persists by copying itself into a specific folder, generating a random service name based on existing svchost.exe-backed services, registering itself as a service, and deleting the original loader artifacts. The malware tampers with file creation time through Kernel32.dll, attempts C&C communication when running as a service, and encrypts stolen host details before transmission. Reported collection includes the login account, operating system version, IP address, and current system time, giving defenders concrete behaviors for service-creation, persistence, and command-and-control detection.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 192.99.223.115 2016-02-23 2020-04-16
IPv4 165.194.123.67 2016-02-23 2020-04-16

Related Reports

« Back