인터넷 공유기 설치파일 위장한 AppleSeed 유포

2022-05-31 Ahnlab AppleSeed distributed disguised as Internet router installation file

https://asec.ahnlab.com/ko/34883/

Thumbnail for 인터넷 공유기 설치파일 위장한 AppleSeed 유포

AhnLab observed AppleSeed malware, a backdoor associated with Kimsuky APT activity, distributed as an executable disguised as an internet router firmware upgrade installer. When run, the file showed a fake firmware-update prompt and opened iptime.com while installing AppleSeed in the background. The malware ran from paths under ProgramData, including Firmware\Microsoft\Windows\Defender\AutoUpdate.dll and Software\ControlSet\Service\ServiceScheduler.dll, with regsvr32 execution and an /i argument used in recent anti-sandbox behavior. AhnLab says AppleSeed can receive C2 commands for information theft and additional payload delivery, with related cases installing RDP Patcher, HVNC, TightVNC, and Metasploit Meterpreter; listed infrastructure included fedra.p-e[.]kr, printware2.000webhostapp[.]com, and leomin.dothome[.]co.kr.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN fedra.p-e.kr 2022-05-31 2023-11-01
HASH 851e33373114fef45d0fe28c6934fa73 2022-05-31 2022-07-08
HASH 9ac572bdca96a833a40edcaa91e04c2b 2022-05-31 2022-07-08
DOMAIN leomin.dothome.co.kr 2022-05-31 2022-07-08
URL http://leomin.dothome.co.kr/upd… 2022-05-31 2022-06-05
HASH 6b10482c939fc33c3a45a17f021df32b 2022-05-31 2022-05-31
HASH c99f6d1c7c0d55ce1453dd08c87ee2b4 2022-05-31 2022-05-31
HASH 39b39ca9cbf9b271590d06dfc68a68b7 2022-05-31 2022-05-31
URL http://fedra.p-e.kr// 2022-05-31 2022-05-31
URL http://printware2.000webhostapp… 2022-05-31 2022-05-31
DOMAIN printware2.000webhostapp.com 2022-05-31 2022-05-31

Related Actors

Related Reports

« Back