북한 해킹 단체 Reaper(리퍼)에서 만든 악성코드-mfc100.dll(2023.5.29)

2023-06-09 Sakai Malware created by North Korean hacking group Reaper - mfc100.dll (2023.5.29)

https://wezard4u.tistory.com/6468

Thumbnail for 북한 해킹 단체 Reaper(리퍼)에서 만든 악성코드-mfc100.dll(2023.5.29)

APT37/Reaper, also known as Group123, Inky Squid, RedEyes, ScarCruft and Ricochet Chollima, is described as using mfc100.dll malware in a May 2023 infection chain focused on South Korean political and organizational targets. The source says the campaign uses an archive and lure file to launch PowerShell, BAT scripting and rundll32 execution before deleting the temporary DLL executable. The malware is associated with credential theft, data exfiltration, screenshots, system information collection, command and shellcode execution, and file management, with cloud-storage-style C2 noted as a Reaper pattern. Representative indicators include the SHA-256 0e926d8b6fbf6f14a2a19d4d4af843253f9f5f6de337956a12dde279f3321d78, naver-file.com, and TCP connections to 5.8.71.81:443 and 8.247.211.254:80.

Indicators of Compromise

Type Value First Seen Last Seen
HASH cb675bbebcc4a77cf5a3b341734b84de 2023-06-09 2023-10-16
HASH 39663e144dc00e3eff004895347a91c… 2023-06-09 2023-10-16
URL https://naver-file.com:443/down… 2023-06-09 2023-10-16
IPv4 5.8.71.81 2023-06-09 2023-10-16
IPv4 8.247.211.254 2023-06-09 2023-10-16
HASH 0e926d8b6fbf6f14a2a19d4d4af8432… 2023-05-01 2023-10-16
DOMAIN naver-file.com 2023-05-01 2023-10-16
DOMAIN malware.ai 2023-06-09 2023-06-09

Related Actors

Related Reports

« Back