북한 해킹 단체 APT37 Reaper(리퍼)에서 만든 악성코드-2023년 11월 청구내역.html(2023.11.07)

2023-11-20 Sakai Malicious code created by North Korean hacking group APT37 Reaper - November 2023 Claim Details.html (2023.11.07)

https://wezard4u.tistory.com/6661

Thumbnail for 북한 해킹 단체 APT37 Reaper(리퍼)에서 만든 악성코드-2023년 11월 청구내역.html(2023.11.07)

The source attributes a November 2023 billing themed HTML and LNK malware chain to APT37, also known as Reaper, Group123, RedEyes, ScarCruft, or Ricochet Chollima. The lure is distributed as a ZIP containing an HWP decoy and a malicious LNK that launches obfuscated PowerShell, extracts embedded HTML and VBS data from the LNK, deletes the original shortcut, and runs a VBS payload from the public Libraries path. The write up frames the activity as part of APT37 tradecraft for espionage and information theft against South Korean and regional targets, with RokRAT style behavior including credential theft, data exfiltration, screenshots, system information collection, command execution, and cloud service based C2. Representative indicators include the defanged URL ebpp.airport[.]kr/mail.do and hashes for the ZIP and LNK samples.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 015ba89bce15c66baebc5fd94d03d19e 2023-11-20 2023-12-18
URL http://ebpp.airport.kr/mail.do 2023-11-20 2023-12-18
DOMAIN ebpp.airport.kr 2023-11-20 2023-12-18
HASH e9a37e9c9ebccce3c3e8cbdd865d25ed 2023-11-20 2023-11-20
HASH 47b4ff5fa114eb477e56fe29969e803… 2023-11-20 2023-11-20
HASH 92ae1fb12ca2907460e120d09e43f35… 2023-11-20 2023-11-20
HASH 6b148003f22e1c10f18de9ca3eb7170… 2023-11-20 2023-11-20
HASH 5e6bda109741fc9a5492030f653fb1f… 2023-11-20 2023-11-20
IPv4 104.244.42.65 2023-11-20 2023-11-20
IPv4 2.18.66.170 2023-11-20 2023-11-20
IPv4 104.85.1.163 2023-11-20 2023-11-20
IPv4 2.23.161.155 2023-11-20 2023-11-20
IPv4 104.86.110.106 2023-11-20 2023-11-20
IPv4 13.49.212.207 2023-11-20 2023-11-20
IPv4 52.142.124.215 2023-11-20 2023-11-20
IPv4 2.22.5.73 2023-11-20 2023-11-20
IPv4 142.250.179.132 2023-11-20 2023-11-20
IPv4 172.64.149.23 2023-11-20 2023-11-20
IPv4 8.247.209.254 2023-11-20 2023-11-20
IPv4 185.26.182.103 2023-11-20 2023-11-20
IPv4 82.145.216.20 2023-11-20 2023-11-20
IPv4 185.15.59.224 2023-11-20 2023-11-20
IPv4 172.64.152.151 2023-11-20 2023-11-20
IPv4 104.18.38.233 2023-11-20 2023-11-20
IPv4 185.26.182.118 2023-11-20 2023-11-20
IPv4 157.240.247.35 2023-11-20 2023-11-20
IPv4 87.248.116.11 2023-11-20 2023-11-20
IPv4 212.82.100.137 2023-11-20 2023-11-20
IPv4 152.199.19.74 2023-11-20 2023-11-20
IPv4 18.65.39.20 2023-11-20 2023-11-20
IPv4 185.26.182.109 2023-11-20 2023-11-20
IPv4 192.229.221.95 2023-11-20 2023-11-20
IPv4 18.185.8.123 2023-11-20 2023-11-20
IPv4 209.140.135.138 2023-11-20 2023-11-20

Related Actors

Related Reports

« Back