인터넷 공유기 설치파일 위장한 AppleSeed 유포
2022-05-31 • Ahnlab • AppleSeed distributed disguised as Internet router installation file •
AhnLab observed AppleSeed malware, a backdoor associated with Kimsuky APT activity, distributed as an executable disguised as an internet router firmware upgrade installer. When run, the file showed a fake firmware-update prompt and opened iptime.com while installing AppleSeed in the background. The malware ran from paths under ProgramData, including Firmware\Microsoft\Windows\Defender\AutoUpdate.dll and Software\ControlSet\Service\ServiceScheduler.dll, with regsvr32 execution and an /i argument used in recent anti-sandbox behavior. AhnLab says AppleSeed can receive C2 commands for information theft and additional payload delivery, with related cases installing RDP Patcher, HVNC, TightVNC, and Metasploit Meterpreter; listed infrastructure included fedra.p-e[.]kr, printware2.000webhostapp[.]com, and leomin.dothome[.]co.kr.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | fedra.p-e.kr | 2022-05-31 | 2023-11-01 |
| HASH | 851e33373114fef45d0fe28c6934fa73 | 2022-05-31 | 2022-07-08 |
| HASH | 9ac572bdca96a833a40edcaa91e04c2b | 2022-05-31 | 2022-07-08 |
| DOMAIN | leomin.dothome.co.kr | 2022-05-31 | 2022-07-08 |
| URL | http://leomin.dothome.co.kr/upd… | 2022-05-31 | 2022-06-05 |
| HASH | 6b10482c939fc33c3a45a17f021df32b | 2022-05-31 | 2022-05-31 |
| HASH | c99f6d1c7c0d55ce1453dd08c87ee2b4 | 2022-05-31 | 2022-05-31 |
| HASH | 39b39ca9cbf9b271590d06dfc68a68b7 | 2022-05-31 | 2022-05-31 |
| URL | http://fedra.p-e.kr// | 2022-05-31 | 2022-05-31 |
| URL | http://printware2.000webhostapp… | 2022-05-31 | 2022-05-31 |
| DOMAIN | printware2.000webhostapp.com | 2022-05-31 | 2022-05-31 |