다양한 원격 제어 도구들을 악용하는 공격자들
2022-10-11 • Ahnlab • Attackers exploiting various remote control tools •
AhnLab reviews how attackers abuse legitimate remote administration tools and malicious RATs to take control of infected systems. The report distinguishes backdoors, remote shells, Remote Access Trojans, and normal tools such as AnyDesk and TeamViewer that can be misused after intrusion. It notes that remote-control capability is often an intermediate stage in larger enterprise attacks, enabling lateral movement, information theft, and later ransomware deployment. Examples include commercial or leaked RAT families such as Remcos, AveMaria, BitRAT, RedLine, and NanoCore, alongside legitimate administration software used to blend into victim environments.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 1aeb95215a633400d90ad8cbca9bc300 | 2022-10-11 | 2022-10-11 |
| HASH | fe1bb6811f5c808414c4a357031c2718 | 2022-10-11 | 2022-10-11 |
| URL | http://bbq.zzhreceive.top/tmate | 2022-10-11 | 2022-10-11 |
| DOMAIN | bbq.zzhreceive.top | 2022-10-11 | 2022-10-11 |
| IPv4 | 58.180.56.28 | 2022-10-11 | 2022-10-11 |
| IPv4 | 106.250.168.50 | 2022-10-11 | 2022-10-11 |
| IPv4 | 119.201.213.146 | 2022-10-11 | 2022-10-11 |
| IPv4 | 183.111.148.147 | 2022-10-11 | 2022-10-11 |