삼성 메신저 사칭 악성코드

2016-01-26 Sands Lab Malware impersonating Samsung Messenger

http://story.malwares.com/70

The excerpt analyzes malware disguised as Samsung's internal messenger, but the body does not attribute the activity to a named threat actor. When executed, the malicious installer launches a decoy Remote Desktop Connection program while running a backdoor that repeatedly attempts to connect to a command server. The backdoor is designed to receive 28 commands and control processes, files, system functions, and network activity, with some command communication encrypted. The report notes the target context as an enterprise environment and warns that sensitive corporate data could be exposed if the command server becomes active; it also provides SHA-256 44884565800EEBF41185861133710B4A42A99D80B6A74436BF788C0E210B9F50 as a sample indicator.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 44884565800eebf41185861133710b4… 2016-01-26 2020-03-09
IPv4 206.248.59.124 2016-01-26 2016-01-26
IPv4 94.199.145.55 2016-01-26 2016-01-26

Related Reports

« Back