발주서, 품의서를 위장한 AppleSeed 유포

2022-06-30 Ahnlab AppleSeed distribution disguised as purchase orders and approval documents

https://asec.ahnlab.com/ko/35781/

Thumbnail for 발주서, 품의서를 위장한 AppleSeed 유포

AhnLab observed AppleSeed malware being distributed in files disguised as purchase orders and approval documents, with the backdoor identified as a tool mainly used by the Kimsuky group. The JSE lure drops both an AppleSeed DLL and a decoy purchase-order PDF under %ProgramData%, then uses regsvr32.exe to decode and run the backdoor and mshta.exe to download and execute an additional script. The script collects host, OS, processor, memory, network, routing, port, ARP, process, service, ProgramFiles, Start Menu, and recent-file information before sending it to C2. The report lists C2 infrastructure including dirwear.000webhostapp.com for information theft and gerter.getenjoyment.net for the AppleSeed backdoor, and warns that the decoy document can hide infection from users.

Indicators of Compromise

Type Value First Seen Last Seen
HASH ec9dcef04c5c89d6107d23b0668cc1c1 2022-06-30 2025-06-09
HASH 1ae2e46aac55e7f92c72b56b387bc945 2022-06-30 2025-06-09
DOMAIN dirwear.000webhostapp.com 2022-06-30 2025-06-09
HASH 7d445b39a090b486aaa002b282b4d8cb 2022-06-30 2022-06-30
HASH 67e7e8600a57e9430a43bf8c5f98c6bd 2022-06-30 2022-06-30
URL http://gerter.getenjoyment.net 2022-06-30 2022-06-30
URL http://dirwear.000webhostapp.com 2022-06-30 2022-06-30
DOMAIN gerter.getenjoyment.net 2022-06-30 2022-06-30

Related Actors

Related Reports

« Back