북한 연관 그룹 추정 PDF 문서를 이용한 APT 공격

2021-08-06 Ahnlab APT attack using PDF documents believed to be related to North Korea

https://asec.ahnlab.com/ko/26183/

Thumbnail for 북한 연관 그룹 추정 PDF 문서를 이용한 APT 공격

AhnLab reports targeted attacks using malicious PDF documents believed to be connected to a North Korea-related group, possibly Kimsuky or Thallium, while noting that imitation by another actor remains possible. The PDFs exploited CVE-2020-9715 in unpatched Adobe Acrobat to execute embedded JavaScript and launch fileless EXE payloads from memory; several lures used inter-Korean relations themes likely aimed at individuals or organizations working on those issues. The malware contacted atwebpages[.]com infrastructure to download additional files, and related DLL samples used XOR encoding, VMProtect, and the export name “FirstFunction.” AhnLab ties the activity to earlier Kimsuky/Thallium-like code style and C2 patterns, and provides hashes plus representative C2 domains for detection.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN atwebpages.com 2018-02-02 2024-09-05
HASH 8b1606f4f2df5d95e00411b4057b3da1 2021-08-06 2021-08-06
HASH a67b0c89812e9517178b8581ff830a38 2021-08-06 2021-08-06
HASH b31aaabc8b39f2854ace7680b34322fe 2021-08-06 2021-08-06
HASH a0c7e9dc69e439cb431e6dea9f0d5930 2021-08-06 2021-08-06
HASH 70294ac8b61bfb936334bcb6e6e8cc50 2021-08-06 2021-08-06
HASH be4daa6400a6e417270e17b67a44ca97 2021-08-06 2021-08-06
HASH 29b28e79d86e4395e223d44d60b14ff4 2021-08-06 2021-08-06
HASH df2ea74328ad43c4225cb6c8aa56f340 2021-08-06 2021-08-06
HASH 906b43cb893e0a57404c8f17085a1f24 2021-08-06 2021-08-06
HASH de2a8a728f81d44562bfd3e91c95f002 2021-08-06 2021-08-06
HASH c9c7d70174e8be8b2cebfeb125be2672 2021-08-06 2021-08-06
HASH 6d6399e5e98164e365029a9b141e1646 2021-08-06 2021-08-06
HASH ffe39eb91e0247fb13bd8fd8152f61a3 2021-08-06 2021-08-06
HASH aa5a3f19e5f7d15b6af37a4f2c8215ee 2021-08-06 2021-08-06
URL http://tktlal3.atwebpages.com 2021-08-06 2021-08-06
URL http://tktlal2.atwebpages.com/c… 2021-08-06 2021-08-06
URL http://dkekftks.atwebpages.com/… 2021-08-06 2021-08-06
URL http://dktkglrkshqhfn.atwebpage… 2021-08-06 2021-08-06
URL http://tktlal2.atwebpages.com/c… 2021-08-06 2021-08-06
URL http://tksRpdl.atwebpages.com 2021-08-06 2021-08-06
URL http://tksRpdl.atwebpages.com/c… 2021-08-06 2021-08-06
URL http://tktlal3.atwebpages.com/c… 2021-08-06 2021-08-06
URL http://tktlal2.atwebpages.com 2021-08-06 2021-08-06
URL http://rhwkdlaktm.atwebpages.com 2021-08-06 2021-08-06
URL http://dktkglrkshqhfn.atwebpage… 2021-08-06 2021-08-06
URL http://dkekftks.atwebpages.com 2021-08-06 2021-08-06
URL http://dkekftks.atwebpages.com/… 2021-08-06 2021-08-06
URL http://tktlal3.atwebpages.com/c… 2021-08-06 2021-08-06
DOMAIN tktlal3.atwebpages.com 2021-08-06 2021-08-06
DOMAIN tktlal2.atwebpages.com 2021-08-06 2021-08-06
DOMAIN tksrpdl.atwebpages.com 2021-08-06 2021-08-06
DOMAIN rhwkdlaktm.atwebpages.com 2021-08-06 2021-08-06
DOMAIN dkekftks.atwebpages.com 2021-08-06 2021-08-06
DOMAIN dktkglrkshqhfn.atwebpages.com 2021-08-06 2021-08-06

Related Actors

Related Reports

« Back