김수키(Kimsuky) 조직, 실제 주민등록등본 파일로 둔갑한 '블루 에스티메이트 Part3' APT 공격 주의

2020-02-06 ESTSecurity Kimsuky organization, beware of ‘Blue Estimate Part3' APT attacks disguised as actual resident registration files

https://blog.alyac.co.kr/2737

Thumbnail for 김수키(Kimsuky) 조직, 실제 주민등록등본 파일로 둔갑한 '블루 에스티메이트 Part3' APT 공격 주의

ESTsecurity reported a February 2020 Operation Blue Estimate variant that masqueraded as a scanned resident-registration PDF tied to a former education-sector official. The malware used a double-extension SCR executable, displayed a decoy image, and dropped a 64-bit DLL named Hero.dll from embedded resources. The sample reused artifacts seen in earlier Blue Estimate activity, including the HelloSidney mutex, Korean-language build traces, MAC address and serial-number collection code, and an AppleSeed64 PDB path. The excerpt identifies mernberinfo.tech at 213.190.6.159 as C2 infrastructure and states that ESTsecurity believed the activity was linked to Kimsuky.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 35d60d2723c649c97b414b3cb701df1c 2019-12-03 2024-08-14
HASH cf87475a87cb2172e73ee6afa7eb6384 2020-02-06 2020-02-06
HASH 20add5eb5fbe527a8b6090a08e7636a6 2020-02-06 2020-02-06
URL https://www.threatinside.com/ 2020-02-06 2020-02-06
IPv4 213.190.6.159 2020-02-06 2020-02-06
HASH da799d16aed24cf4f8ec62d5048afd1a 2020-01-23 2020-02-06

Related Actors

Related Reports

« Back