인터넷 쇼핑몰 I사 해킹에 사용된 악성코드 상세 분석

2016-08-04 NProtect Detailed analysis of malware used in hacking of Internet shopping mall company I

https://isarc.tachyonlab.com/544

Thumbnail for 인터넷 쇼핑몰 I사 해킹에 사용된 악성코드 상세 분석

A Korean shopping mall incident involved a suspected APT malware sample named “OurFamily.abcd.scr” that was reportedly distributed as an email attachment and disguised as a Windows screensaver file. When executed, the SCR dropper created msoia.exe under a Microsoft Office-looking path, copied itself as ielowutil.exe under an Internet Explorer compatibility path, and used autostart-style execution arguments. The ielowutil.exe component supported ten commands, mainly for collecting and sending infected PC information such as documents, media, and process data to attacker-controlled servers, with one command used to download an additional module. The malware attempted connections to servers located in Honduras, Taiwan, and New Zealand and loaded a downloaded iehmmapi.dll module, making the intrusion significant because follow-on modules could expand impact beyond the initial information-stealing behavior.

Related Reports

« Back