북한 해킹 단체 Reaper(리퍼)에서 만든 후쿠시마 오염수 방류(후쿠시마 처리수) 내용을 악용한 악성코드-1.chm(2023.9.5)

2023-09-07 Sakai Malicious code created by the North Korean hacking group Reaper that exploits the contents of Fukushima contaminated water discharge (Fukushima treated water) - 1.chm (2023.9.5)

https://wezard4u.tistory.com/6580

Thumbnail for 북한 해킹 단체 Reaper(리퍼)에서 만든 후쿠시마 오염수 방류(후쿠시마 처리수) 내용을 악용한 악성코드-1.chm(2023.9.5)

The source analyzes a Reaper/ScarCruft CHM malware sample using the Fukushima treated-water discharge topic as a Korean-language lure. The CHM `1.chm` runs `mshta.exe` against `navercorp.ru/dashboard/image/202302/4.html`, shows decoy news-style text about Japanese beer sales in Korea, and registers a Run key so the command re-executes after reboot. The embedded PowerShell decodes to a backdoor that builds victim identifiers from the computer and user name, communicates with `navercorp.ru/dashboard/image/202302/com.php?U=`, and supports file upload and command handling. The report provides hashes for the CHM and describes persistence through `HKCU\Software\Microsoft\Windows\CurrentVersion\Run`.

Indicators of Compromise

Type Value First Seen Last Seen
HASH b31b89e646de6e9c5cbe21798e0157f… 2023-09-07 2023-09-13
URL http://navercorp.ru/dashboard/i… 2023-09-04 2023-09-08
URL http://navercorp.ru/dashboard/i… 2023-09-04 2023-09-08
DOMAIN navercorp.ru 2023-09-04 2023-09-08
HASH a7398bdf6d742d8f76219b92893b8c4… 2023-09-07 2023-09-07
HASH 9e6a2914a35256dd450db549fb975f45 2023-09-06 2023-09-07

Related Actors

Related Reports

« Back