발주서, 품의서를 위장한 AppleSeed 유포
2022-06-30 • Ahnlab • AppleSeed distribution disguised as purchase orders and approval documents •
AhnLab observed AppleSeed malware being distributed in files disguised as purchase orders and approval documents, with the backdoor identified as a tool mainly used by the Kimsuky group. The JSE lure drops both an AppleSeed DLL and a decoy purchase-order PDF under %ProgramData%, then uses regsvr32.exe to decode and run the backdoor and mshta.exe to download and execute an additional script. The script collects host, OS, processor, memory, network, routing, port, ARP, process, service, ProgramFiles, Start Menu, and recent-file information before sending it to C2. The report lists C2 infrastructure including dirwear.000webhostapp.com for information theft and gerter.getenjoyment.net for the AppleSeed backdoor, and warns that the decoy document can hide infection from users.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | ec9dcef04c5c89d6107d23b0668cc1c1 | 2022-06-30 | 2025-06-09 |
| HASH | 1ae2e46aac55e7f92c72b56b387bc945 | 2022-06-30 | 2025-06-09 |
| DOMAIN | dirwear.000webhostapp.com | 2022-06-30 | 2025-06-09 |
| HASH | 7d445b39a090b486aaa002b282b4d8cb | 2022-06-30 | 2022-06-30 |
| HASH | 67e7e8600a57e9430a43bf8c5f98c6bd | 2022-06-30 | 2022-06-30 |
| URL | http://gerter.getenjoyment.net | 2022-06-30 | 2022-06-30 |
| URL | http://dirwear.000webhostapp.com | 2022-06-30 | 2022-06-30 |
| DOMAIN | gerter.getenjoyment.net | 2022-06-30 | 2022-06-30 |