북한 해킹 단체 APT37 Reaper(리퍼)에서 만든 악성코드-2023년 11월 청구내역.html(2023.11.07)
2023-11-20 • Sakai • Malicious code created by North Korean hacking group APT37 Reaper - November 2023 Claim Details.html (2023.11.07) •
The source attributes a November 2023 billing themed HTML and LNK malware chain to APT37, also known as Reaper, Group123, RedEyes, ScarCruft, or Ricochet Chollima. The lure is distributed as a ZIP containing an HWP decoy and a malicious LNK that launches obfuscated PowerShell, extracts embedded HTML and VBS data from the LNK, deletes the original shortcut, and runs a VBS payload from the public Libraries path. The write up frames the activity as part of APT37 tradecraft for espionage and information theft against South Korean and regional targets, with RokRAT style behavior including credential theft, data exfiltration, screenshots, system information collection, command execution, and cloud service based C2. Representative indicators include the defanged URL ebpp.airport[.]kr/mail.do and hashes for the ZIP and LNK samples.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 015ba89bce15c66baebc5fd94d03d19e | 2023-11-20 | 2023-12-18 |
| URL | http://ebpp.airport.kr/mail.do | 2023-11-20 | 2023-12-18 |
| DOMAIN | ebpp.airport.kr | 2023-11-20 | 2023-12-18 |
| HASH | e9a37e9c9ebccce3c3e8cbdd865d25ed | 2023-11-20 | 2023-11-20 |
| HASH | 47b4ff5fa114eb477e56fe29969e803… | 2023-11-20 | 2023-11-20 |
| HASH | 92ae1fb12ca2907460e120d09e43f35… | 2023-11-20 | 2023-11-20 |
| HASH | 6b148003f22e1c10f18de9ca3eb7170… | 2023-11-20 | 2023-11-20 |
| HASH | 5e6bda109741fc9a5492030f653fb1f… | 2023-11-20 | 2023-11-20 |
| IPv4 | 104.244.42.65 | 2023-11-20 | 2023-11-20 |
| IPv4 | 2.18.66.170 | 2023-11-20 | 2023-11-20 |
| IPv4 | 104.85.1.163 | 2023-11-20 | 2023-11-20 |
| IPv4 | 2.23.161.155 | 2023-11-20 | 2023-11-20 |
| IPv4 | 104.86.110.106 | 2023-11-20 | 2023-11-20 |
| IPv4 | 13.49.212.207 | 2023-11-20 | 2023-11-20 |
| IPv4 | 52.142.124.215 | 2023-11-20 | 2023-11-20 |
| IPv4 | 2.22.5.73 | 2023-11-20 | 2023-11-20 |
| IPv4 | 142.250.179.132 | 2023-11-20 | 2023-11-20 |
| IPv4 | 172.64.149.23 | 2023-11-20 | 2023-11-20 |
| IPv4 | 8.247.209.254 | 2023-11-20 | 2023-11-20 |
| IPv4 | 185.26.182.103 | 2023-11-20 | 2023-11-20 |
| IPv4 | 82.145.216.20 | 2023-11-20 | 2023-11-20 |
| IPv4 | 185.15.59.224 | 2023-11-20 | 2023-11-20 |
| IPv4 | 172.64.152.151 | 2023-11-20 | 2023-11-20 |
| IPv4 | 104.18.38.233 | 2023-11-20 | 2023-11-20 |
| IPv4 | 185.26.182.118 | 2023-11-20 | 2023-11-20 |
| IPv4 | 157.240.247.35 | 2023-11-20 | 2023-11-20 |
| IPv4 | 87.248.116.11 | 2023-11-20 | 2023-11-20 |
| IPv4 | 212.82.100.137 | 2023-11-20 | 2023-11-20 |
| IPv4 | 152.199.19.74 | 2023-11-20 | 2023-11-20 |
| IPv4 | 18.65.39.20 | 2023-11-20 | 2023-11-20 |
| IPv4 | 185.26.182.109 | 2023-11-20 | 2023-11-20 |
| IPv4 | 192.229.221.95 | 2023-11-20 | 2023-11-20 |
| IPv4 | 18.185.8.123 | 2023-11-20 | 2023-11-20 |
| IPv4 | 209.140.135.138 | 2023-11-20 | 2023-11-20 |