김수키(Kimsuky) 조직, 실제 주민등록등본 파일로 둔갑한 '블루 에스티메이트 Part3' APT 공격 주의
2020-02-06 • ESTSecurity • Kimsuky organization, beware of ‘Blue Estimate Part3' APT attacks disguised as actual resident registration files •
ESTsecurity reported a February 2020 Operation Blue Estimate variant that masqueraded as a scanned resident-registration PDF tied to a former education-sector official. The malware used a double-extension SCR executable, displayed a decoy image, and dropped a 64-bit DLL named Hero.dll from embedded resources. The sample reused artifacts seen in earlier Blue Estimate activity, including the HelloSidney mutex, Korean-language build traces, MAC address and serial-number collection code, and an AppleSeed64 PDB path. The excerpt identifies mernberinfo.tech at 213.190.6.159 as C2 infrastructure and states that ESTsecurity believed the activity was linked to Kimsuky.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 35d60d2723c649c97b414b3cb701df1c | 2019-12-03 | 2024-08-14 |
| HASH | cf87475a87cb2172e73ee6afa7eb6384 | 2020-02-06 | 2020-02-06 |
| HASH | 20add5eb5fbe527a8b6090a08e7636a6 | 2020-02-06 | 2020-02-06 |
| URL | https://www.threatinside.com/ | 2020-02-06 | 2020-02-06 |
| IPv4 | 213.190.6.159 | 2020-02-06 | 2020-02-06 |
| HASH | da799d16aed24cf4f8ec62d5048afd1a | 2020-01-23 | 2020-02-06 |