인터넷 쇼핑몰 I사 해킹에 사용된 악성코드 상세 분석
2016-08-04 • NProtect • Detailed analysis of malware used in hacking of Internet shopping mall company I •
A Korean shopping mall incident involved a suspected APT malware sample named “OurFamily.abcd.scr” that was reportedly distributed as an email attachment and disguised as a Windows screensaver file. When executed, the SCR dropper created msoia.exe under a Microsoft Office-looking path, copied itself as ielowutil.exe under an Internet Explorer compatibility path, and used autostart-style execution arguments. The ielowutil.exe component supported ten commands, mainly for collecting and sending infected PC information such as documents, media, and process data to attacker-controlled servers, with one command used to download an additional module. The malware attempted connections to servers located in Honduras, Taiwan, and New Zealand and loaded a downloaded iehmmapi.dll module, making the intrusion significant because follow-on modules could expand impact beyond the initial information-stealing behavior.